< Back to situations

This situation has concluded

It was preserved as a record on August 29; the timeline below shows how it unfolded, with sources. Get the briefing to follow the top situations still developing: three emails a week, sourced and in order.

[SITUATION] · [QUIET] · [TECHNOLOGY]

10 clusters · 51 sources · 45 days · First seen · Last updated

WordPress WP2Shell chain prompts forced updates

Overview

Mid‑June 2026 attackers compromised the UpdraftPlus plugin, injecting malicious JavaScript that created hidden admin accounts and a back‑door, affecting about 1.2 million WordPress sites. A concurrent SocGholish campaign and flaws in Gravity SMTP (CVE‑2026‑4020) and ShapedPlugin (CVE‑2026‑49777) added further supply‑chain risk. On 17 July a critical core chain—WP2Shell (CVE‑2026‑63030) combined with an SQL‑injection (CVE‑2026‑60137)—enabled unauthenticated remote code execution via the REST‑API batch endpoint. Emergency core releases (6.9.5, 7.0.2) forced automatic updates for an estimated 500 million installations, and national cyber agencies across Europe and the United States issued urgent warnings, recommending patching, web‑application firewalls and persistent object caching. Researchers publicly identified the chain on 20 July, noting AI assistance in its discovery. On 22 July the German BSI highlighted a high‑risk 7‑Zip flaw (versions 26.02+) and urged immediate updates, while Spain’s INCIBE issued bulletins covering the WP2Shell RCE, the SQL‑injection, and a Linux‑kernel netfilter use‑after‑free (CVE‑2023‑3390), advising upgrades to WordPress 6.9.5, 6.8.6 or the 7.1 beta2. A BSI alert on 29 July classified WP2Shell as orange, reporting over 11 million blocked exploit attempts. Experts continue to stress enabling automatic updates, applying WAF rules, and using persistent object caching to mitigate the evolving attack chain.

Entities

Searchlight Cyber · Wordfence · Bundesamt für Sicherheit in der Informationstechnik (BSI) · WordPress · WP2Shell

Timeline

  1. about 2 months ago

    [TECHNOLOGY] 2 sources
    WordPress core flaw WP2Shell enables remote server takeover

    WP2Shell, a WordPress core flaw combining two CVEs, enables pre‑auth remote code execution; updates released 17 July 2026, with over 11 million attacks blocked.

  2. 2 months ago

    [TECHNOLOGY] 3 sources
    INCIBE issues security bulletins on critical WordPress and Linux kernel flaws

    INCIBE's July 2026 bulletins warn of high‑severity Linux kernel and multiple critical WordPress flaws, including remote code execution and SQL injection, and provide patch recommendations.

  3. 2 months ago

    [TECHNOLOGY] 5 sources
    Critical WordPress and 7‑Zip vulnerabilities prompt urgent updates

    WordPress and 7‑Zip have critical security flaws; upgrade to WordPress 6.9.5/7.0.2+ and 7‑Zip 26.02+, enable auto‑updates, BSI urges immediate action.

  4. 2 months ago

    [TECHNOLOGY] 17 sources
    WordPress WP2Shell flaw exploited, millions of sites urged to update

    A critical WordPress flaw (WP2Shell) linking two CVEs lets attackers execute code without login; millions of sites remain vulnerable and experts urge immediate update to the latest versions.

  5. 2 months ago

    [TECHNOLOGY] 4 sources
    Microsoft patches 570 flaws as ransomware and WordPress exploits surge

    July brought a surge of ransomware, WordPress RCE and AI‑tool exploits; Microsoft released a record patch fixing 570 bugs, 59 critical, including zero‑days in AD FS, SharePoint, BitLocker and Copilot.

  6. 2 months ago

    [TECHNOLOGY] 14 sources
    WordPress issues emergency patch for critical wp2shell remote‑code execution flaw

    WordPress patched a critical wp2shell RCE bug affecting 6.9.x and 7.0.x versions, forcing updates for an estimated 500 million sites.

  7. 3 months ago

    [TECHNOLOGY] 2 sources
    WordPress plugins face severe backdoor supply‑chain attack and active SMTP data‑leak exploit

    Two major WordPress security issues emerged: a supply‑chain backdoor in ShapedPlugin’s premium plugins (CVE‑2026‑49777, CVSS 10) stealing admin data, and active exploitation of a Gravity SMTP flaw (CVE‑2026‑402

  8. 3 months ago

    [TECHNOLOGY] 2 sources
    WordPress sites face AI‑driven traffic loss and rising security threats

    Websites face AI‑driven traffic drops and must become AI‑trusted sources, while WordPress sites confront supply‑chain hacks, SocGholish attacks and plugin vulnerabilities.

  9. 3 months ago

    [TECHNOLOGY] 2 sources
    WordPress Plugin Supply-Chain Attack Hits Over 1.2 Million Sites

    A supply‑chain attack on WordPress plugins OptinMonster, TrustPulse and PushEngage injected malicious code via the CDN, creating hidden admin accounts and backdoors on over 1.2 million sites; providers have now

  10. 3 months ago

    [TECHNOLOGY] 2 sources
    WordPress admins hit by tampered CDN scripts for TrustPulse, OptinMonster, PushEngage

    A June 2026 CDN breach let attackers serve tampered JavaScript for TrustPulse, OptinMonster and PushEngage, creating hidden WordPress admin accounts and backdoors; only sites with logged‑in admins were affected

Sources

all-about-security.de · b2b-cyber-security.de · b2k-media.de · bitskin.de · blogspan.net · borncity.com · brandspurng.com · cinemagia.wordpress.com · clubic.com · countryrebel.com · dasauge.de · digitalmarketreports.com · es.wordpress.org · fishuniversity.com · flagthis.com · floranews.nl · gazeta-lokalna.pl · globalsecuritymag.fr · horizon3.ai · hurlinggalaxy.com · hvg.hu · incibe.es · infoguerra.com.br · inteco.es · it-administrator.de · it-boltwise.de · itnerd.blog · jaw.pl · magazine-art.com · managerplus.pl · michael-bickel.de · moncloa.com · news.co.za · pioneer.com · rbfirehose.com · rockyharbour.ca · sadio.org.ar · security-insider.de · security.nl · securityaffairs.co · spip-contrib.net · stranotizie.it · tele.org · telepolis.pl · thehackernews.com · thenextweb.com · vat.pravda.sk · wasi0013.com