Public Exploits Released for WordPress Core 'wp2shell' RCE Flaws
Public exploits are now available for the critical ‘wp2shell’ remote code execution vulnerabilities affecting WordPress Core. These flaws allow unauthenticated attackers to run code on vulnerable WordPress sites, including bare installations without plugins. Administrators are urged to patch their sites immediately, especially since the full mechanism and a working proof-of-concept have been published, impacting WordPress versions 6.9 and 7.0.