
WordPress Attacks Using wp2shell: Why the Update Alone Isn’t Enough to Give the All-Clear
Since July 17, 2026, a critical vulnerability in the WordPress core has been actively exploited—without requiring a login or a plugin, on a default installation. Anyone who has updated since then is protected against new attacks. However, the version number does not indicate whether anyone gained access to the system between July 17 and the







































































































