WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Summary
Attackers are actively exploiting two critical vulnerabilities in WordPress, collectively known as wp2shell. These flaws allow for unauthenticated remote code execution and complete website compromise, leading to mass scanning for vulnerable sites.
IFF Assessment
FOE
The exploitation of critical vulnerabilities enabling unauthenticated remote code execution and complete website compromise is detrimental to website defenders.
Severity
9.8
Critical
Defender Context
Defenders should prioritize patching WordPress sites immediately to mitigate the risk of compromise from the wp2shell vulnerabilities. Monitoring for mass scanning activity targeting WordPress endpoints can also help identify potential exploitation attempts.