Skip to content

WordPress: wp2shell attack enables remote code execution

Person using a laptop showing a software update screen on a wooden desk with a notebook, plant, and monitor nearby.

Researchers have identified a new attack capable of targeting WordPress websites - a platform used by 40% of all websites - with no preconditions required. An update is already available to address the vulnerabilities exploited by the attack.

Even if you do not run a WordPress site yourself, you are likely to use the software every day without realising it. Although precise figures are unavailable, more than 500 million websites are thought to rely on this CMS. WordPress is also estimated to hold a market share of over 40% of all websites worldwide.

wp2shell targets WordPress core

Yet this software, which is a fundamental part of the web, is now under threat. On Friday, Searchlight Cyber researchers announced that they had uncovered a new attack, called wp2shell, which targets the WordPress core to achieve remote code execution.

An update is already available

“This attack requires no prerequisites and can be exploited by an anonymous user on a standard WordPress installation without any plugins,” the researchers said, underlining how dangerous the attack is. They also urged WordPress site publishers to install version 7.0.2 or 6.9.5 as soon as possible to stay protected. WordPress, meanwhile, says that it has enabled “forced updates” on the affected sites because of the issue’s “severity”. It also states that version 7.0.2 fixes two vulnerabilities, one of which is critical.

Searchlight Cyber has also launched a website that can “scan” any WordPress site to determine whether it is vulnerable to this attack.

For websites that are not yet able to install the update, Searchlight Cyber has outlined temporary mitigations. However, the company warns that these “solutions may affect the legitimate use of the site and should only be considered as temporary emergency measures pending the update.” The update therefore remains essential.

Comments

No comments yet. Be the first to comment!

Leave a Comment