Three weeks after the WordPress security releases, wp2shell probing is still showing up in vendor telemetry.
Still worth a version check on every site you manage. Also look for admins you did not create.
Protect your WordPress site with ease.
Firewall, malware scanner, login protection & WooCommerce security in one powerful plugin. wpsecurityninja.com
- wp2shell update: FortiGuard still blocked ~4.6k exploitation attempts in one day (≈88k over 7 days). Core issue. Fixes: 6.8.6 / 6.9.5 / 7.0.2. Confirm yourself, then check for rogue admins.
- Still worth a version check on every WordPress site you manage. wp2shell is core, not a plugin. Fixes: 6.8.6, 6.9.5, 7.0.2. Confirm yourself. Also look for admins you did not create.
- wp2shell update: researchers showed a path past PHP hardening to Linux root after a successful foothold. Step one is unchanged: WordPress 6.8.6 / 6.9.5 / 7.0.2 or newer, then check for compromise.
- wp2shell has another nasty twist: a failed exploit may leave behind a rogue WordPress admin, even when no webshell is visible. In one real incident, attackers succeeded on their third attempt. What to check now: wpsecurityninja.com/wp2shell/ #WordPress #WordPressSecurity #WPSecurity

