CRITICAL
WordPress Core "wp2shell" RCE Flaws Get Public Exploits, Patch Now
Public proof-of-concept exploits have been released for a set of critical remote code execution vulnerabilities in WordPress Core, tracked under the name “wp2shell.” The public availability of working exploit code lowers the bar for opportunistic attacks against unpatched sites. Patches are already available, so this is not an active zero-day, but administrators should update WordPress Core immediately and check internet-facing installs for signs of compromise.