< Back to situations

We’ll email you as it develops, and you can follow the whole thread from day one.

[SITUATION] · [ACTIVE]

7 clusters · 38 sources · 36 days · First seen · Last updated

Categories: TECHNOLOGY

WordPress WP2Shell chain prompts forced updates

Overview

Mid‑June 2026 attackers hijacked the UpdraftPlus plugin, injecting malicious JavaScript that created hidden admin accounts and installed a back‑door, compromising about 1.2 million WordPress sites. A concurrent “SocGholish” campaign and flaws in Gravity SMTP (CVE‑2026‑4020) and ShapedPlugin (CVE‑2026‑49777) added further supply‑chain risk. On 17 July a critical core flaw, wp2shell (CVE‑2026‑63030), combined with an SQL‑injection (CVE‑2026‑60137) to enable unauthenticated remote code execution via the REST‑API batch endpoint. Emergency WordPress releases (6.9.5, 7.0.2) forced automatic updates for an estimated 500 million installations. Researchers confirmed the chain had existed since 2020 and released proof‑of‑concept code; subsequent analysis showed multiple threat actors began exploiting it in the wild. National cyber agencies in Portugal, Poland, the Netherlands and now Hungary issued urgent warnings, urging administrators to apply the patches, deploy web‑application firewalls, and enable persistent object caching. The combined vulnerabilities affect default WordPress 6.9.0‑6.9.4 and 7.0.0‑7.0.1, with the SQL‑injection also impacting 6.8.0‑6.8.5, potentially exposing up to 90 million sites. The episode underscores the growing impact of supply‑chain attacks on the WordPress ecosystem.

Timeline

  1. 1 day ago

    [TECHNOLOGY] 13 sources
    WordPress Critical Vulnerabilities Trigger Global Forced Updates

    Critical WordPress Core flaws (WP2Shell) enable unauthenticated RCE, affecting millions of sites; AI‑found, actively exploited, and fixed by forced updates.

  2. 2 days ago

    [TECHNOLOGY] 4 sources
    Microsoft patches 570 flaws as ransomware and WordPress exploits surge

    July brought a surge of ransomware, WordPress RCE and AI‑tool exploits; Microsoft released a record patch fixing 570 bugs, 59 critical, including zero‑days in AD FS, SharePoint, BitLocker and Copilot.

  3. 4 days ago

    [TECHNOLOGY] 14 sources
    WordPress issues emergency patch for critical wp2shell remote‑code execution flaw

    WordPress patched a critical wp2shell RCE bug affecting 6.9.x and 7.0.x versions, forcing updates for an estimated 500 million sites.

  4. 29 days ago

    [TECHNOLOGY] 2 sources
    WordPress plugins face severe backdoor supply‑chain attack and active SMTP data‑leak exploit

    Two major WordPress security issues emerged: a supply‑chain backdoor in ShapedPlugin’s premium plugins (CVE‑2026‑49777, CVSS 10) stealing admin data, and active exploitation of a Gravity SMTP flaw (CVE‑2026‑402

  5. about 1 month ago

    [TECHNOLOGY] 2 sources
    WordPress sites face AI‑driven traffic loss and rising security threats

    Websites face AI‑driven traffic drops and must become AI‑trusted sources, while WordPress sites confront supply‑chain hacks, SocGholish attacks and plugin vulnerabilities.

  6. about 1 month ago

    [TECHNOLOGY] 2 sources
    WordPress Plugin Supply-Chain Attack Hits Over 1.2 Million Sites

    A supply‑chain attack on WordPress plugins OptinMonster, TrustPulse and PushEngage injected malicious code via the CDN, creating hidden admin accounts and backdoors on over 1.2 million sites; providers have now

  7. about 1 month ago

    [TECHNOLOGY] 2 sources
    WordPress admins hit by tampered CDN scripts for TrustPulse, OptinMonster, PushEngage

    A June 2026 CDN breach let attackers serve tampered JavaScript for TrustPulse, OptinMonster and PushEngage, creating hidden WordPress admin accounts and backdoors; only sites with logged‑in admins were affected

Sources

all-about-security.de · b2b-cyber-security.de · blogspan.net · borncity.com · brandspurng.com · cinemagia.wordpress.com · clubic.com · countryrebel.com · digitalmarketreports.com · es.wordpress.org · fishuniversity.com · flagthis.com · floranews.nl · gazeta-lokalna.pl · horizon3.ai · hvg.hu · it-administrator.de · it-boltwise.de · itnerd.blog · magazine-art.com · managerplus.pl · michael-bickel.de · news.co.za · pioneer.com · rbfirehose.com · rockyharbour.ca · sadio.org.ar · security-insider.de · security.nl · securityaffairs.co · spip-contrib.net · stranotizie.it · tele.org · telepolis.pl · thehackernews.com · vat.pravda.sk · wasi0013.com · youcangetitdone.com