This situation has concluded
It was preserved as a record on August 29; the timeline below shows how it unfolded, with sources. Get the briefing to follow the top situations still developing: three emails a week, sourced and in order.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
10 clusters · 51 sources · 45 days · First seen · Last updated
WordPress WP2Shell chain prompts forced updates
Overview
Mid‑June 2026 attackers compromised the UpdraftPlus plugin, injecting malicious JavaScript that created hidden admin accounts and a back‑door, affecting about 1.2 million WordPress sites. A concurrent SocGholish campaign and flaws in Gravity SMTP (CVE‑2026‑4020) and ShapedPlugin (CVE‑2026‑49777) added further supply‑chain risk. On 17 July a critical core chain—WP2Shell (CVE‑2026‑63030) combined with an SQL‑injection (CVE‑2026‑60137)—enabled unauthenticated remote code execution via the REST‑API batch endpoint. Emergency core releases (6.9.5, 7.0.2) forced automatic updates for an estimated 500 million installations, and national cyber agencies across Europe and the United States issued urgent warnings, recommending patching, web‑application firewalls and persistent object caching. Researchers publicly identified the chain on 20 July, noting AI assistance in its discovery. On 22 July the German BSI highlighted a high‑risk 7‑Zip flaw (versions 26.02+) and urged immediate updates, while Spain’s INCIBE issued bulletins covering the WP2Shell RCE, the SQL‑injection, and a Linux‑kernel netfilter use‑after‑free (CVE‑2023‑3390), advising upgrades to WordPress 6.9.5, 6.8.6 or the 7.1 beta2. A BSI alert on 29 July classified WP2Shell as orange, reporting over 11 million blocked exploit attempts. Experts continue to stress enabling automatic updates, applying WAF rules, and using persistent object caching to mitigate the evolving attack chain.
Entities
Searchlight Cyber · Wordfence · Bundesamt für Sicherheit in der Informationstechnik (BSI) · WordPress · WP2Shell
Timeline
-
about 2 months ago
[TECHNOLOGY] 2 sourcesWordPress core flaw WP2Shell enables remote server takeoverWP2Shell, a WordPress core flaw combining two CVEs, enables pre‑auth remote code execution; updates released 17 July 2026, with over 11 million attacks blocked.
-
2 months ago
[TECHNOLOGY] 3 sourcesINCIBE issues security bulletins on critical WordPress and Linux kernel flawsINCIBE's July 2026 bulletins warn of high‑severity Linux kernel and multiple critical WordPress flaws, including remote code execution and SQL injection, and provide patch recommendations.
-
2 months ago
[TECHNOLOGY] 5 sourcesCritical WordPress and 7‑Zip vulnerabilities prompt urgent updatesWordPress and 7‑Zip have critical security flaws; upgrade to WordPress 6.9.5/7.0.2+ and 7‑Zip 26.02+, enable auto‑updates, BSI urges immediate action.
-
2 months ago
[TECHNOLOGY] 17 sourcesWordPress WP2Shell flaw exploited, millions of sites urged to updateA critical WordPress flaw (WP2Shell) linking two CVEs lets attackers execute code without login; millions of sites remain vulnerable and experts urge immediate update to the latest versions.
-
2 months ago
[TECHNOLOGY] 4 sourcesMicrosoft patches 570 flaws as ransomware and WordPress exploits surgeJuly brought a surge of ransomware, WordPress RCE and AI‑tool exploits; Microsoft released a record patch fixing 570 bugs, 59 critical, including zero‑days in AD FS, SharePoint, BitLocker and Copilot.
-
2 months ago
[TECHNOLOGY] 14 sourcesWordPress issues emergency patch for critical wp2shell remote‑code execution flawWordPress patched a critical wp2shell RCE bug affecting 6.9.x and 7.0.x versions, forcing updates for an estimated 500 million sites.
-
3 months ago
[TECHNOLOGY] 2 sourcesWordPress plugins face severe backdoor supply‑chain attack and active SMTP data‑leak exploitTwo major WordPress security issues emerged: a supply‑chain backdoor in ShapedPlugin’s premium plugins (CVE‑2026‑49777, CVSS 10) stealing admin data, and active exploitation of a Gravity SMTP flaw (CVE‑2026‑402
-
3 months ago
[TECHNOLOGY] 2 sourcesWordPress sites face AI‑driven traffic loss and rising security threatsWebsites face AI‑driven traffic drops and must become AI‑trusted sources, while WordPress sites confront supply‑chain hacks, SocGholish attacks and plugin vulnerabilities.
-
3 months ago
[TECHNOLOGY] 2 sourcesWordPress Plugin Supply-Chain Attack Hits Over 1.2 Million SitesA supply‑chain attack on WordPress plugins OptinMonster, TrustPulse and PushEngage injected malicious code via the CDN, creating hidden admin accounts and backdoors on over 1.2 million sites; providers have now
-
3 months ago
[TECHNOLOGY] 2 sourcesWordPress admins hit by tampered CDN scripts for TrustPulse, OptinMonster, PushEngageA June 2026 CDN breach let attackers serve tampered JavaScript for TrustPulse, OptinMonster and PushEngage, creating hidden WordPress admin accounts and backdoors; only sites with logged‑in admins were affected
Sources
all-about-security.de · b2b-cyber-security.de · b2k-media.de · bitskin.de · blogspan.net · borncity.com · brandspurng.com · cinemagia.wordpress.com · clubic.com · countryrebel.com · dasauge.de · digitalmarketreports.com · es.wordpress.org · fishuniversity.com · flagthis.com · floranews.nl · gazeta-lokalna.pl · globalsecuritymag.fr · horizon3.ai · hurlinggalaxy.com · hvg.hu · incibe.es · infoguerra.com.br · inteco.es · it-administrator.de · it-boltwise.de · itnerd.blog · jaw.pl · magazine-art.com · managerplus.pl · michael-bickel.de · moncloa.com · news.co.za · pioneer.com · rbfirehose.com · rockyharbour.ca · sadio.org.ar · security-insider.de · security.nl · securityaffairs.co · spip-contrib.net · stranotizie.it · tele.org · telepolis.pl · thehackernews.com · thenextweb.com · vat.pravda.sk · wasi0013.com