Get alerts on this situation
We’ll email you as it develops, and you can follow the whole thread from day one.
Unsubscribe anytime.
[SITUATION] · [ACTIVE]
7 clusters · 38 sources · 36 days · First seen · Last updated
Categories: TECHNOLOGY
WordPress WP2Shell chain prompts forced updates
Overview
Mid‑June 2026 attackers hijacked the UpdraftPlus plugin, injecting malicious JavaScript that created hidden admin accounts and installed a back‑door, compromising about 1.2 million WordPress sites. A concurrent “SocGholish” campaign and flaws in Gravity SMTP (CVE‑2026‑4020) and ShapedPlugin (CVE‑2026‑49777) added further supply‑chain risk. On 17 July a critical core flaw, wp2shell (CVE‑2026‑63030), combined with an SQL‑injection (CVE‑2026‑60137) to enable unauthenticated remote code execution via the REST‑API batch endpoint. Emergency WordPress releases (6.9.5, 7.0.2) forced automatic updates for an estimated 500 million installations. Researchers confirmed the chain had existed since 2020 and released proof‑of‑concept code; subsequent analysis showed multiple threat actors began exploiting it in the wild. National cyber agencies in Portugal, Poland, the Netherlands and now Hungary issued urgent warnings, urging administrators to apply the patches, deploy web‑application firewalls, and enable persistent object caching. The combined vulnerabilities affect default WordPress 6.9.0‑6.9.4 and 7.0.0‑7.0.1, with the SQL‑injection also impacting 6.8.0‑6.8.5, potentially exposing up to 90 million sites. The episode underscores the growing impact of supply‑chain attacks on the WordPress ecosystem.
Timeline
-
1 day ago
[TECHNOLOGY] 13 sourcesWordPress Critical Vulnerabilities Trigger Global Forced UpdatesCritical WordPress Core flaws (WP2Shell) enable unauthenticated RCE, affecting millions of sites; AI‑found, actively exploited, and fixed by forced updates.
-
2 days ago
[TECHNOLOGY] 4 sourcesMicrosoft patches 570 flaws as ransomware and WordPress exploits surgeJuly brought a surge of ransomware, WordPress RCE and AI‑tool exploits; Microsoft released a record patch fixing 570 bugs, 59 critical, including zero‑days in AD FS, SharePoint, BitLocker and Copilot.
-
4 days ago
[TECHNOLOGY] 14 sourcesWordPress issues emergency patch for critical wp2shell remote‑code execution flawWordPress patched a critical wp2shell RCE bug affecting 6.9.x and 7.0.x versions, forcing updates for an estimated 500 million sites.
-
29 days ago
[TECHNOLOGY] 2 sourcesWordPress plugins face severe backdoor supply‑chain attack and active SMTP data‑leak exploitTwo major WordPress security issues emerged: a supply‑chain backdoor in ShapedPlugin’s premium plugins (CVE‑2026‑49777, CVSS 10) stealing admin data, and active exploitation of a Gravity SMTP flaw (CVE‑2026‑402
-
about 1 month ago
[TECHNOLOGY] 2 sourcesWordPress sites face AI‑driven traffic loss and rising security threatsWebsites face AI‑driven traffic drops and must become AI‑trusted sources, while WordPress sites confront supply‑chain hacks, SocGholish attacks and plugin vulnerabilities.
-
about 1 month ago
[TECHNOLOGY] 2 sourcesWordPress Plugin Supply-Chain Attack Hits Over 1.2 Million SitesA supply‑chain attack on WordPress plugins OptinMonster, TrustPulse and PushEngage injected malicious code via the CDN, creating hidden admin accounts and backdoors on over 1.2 million sites; providers have now
-
about 1 month ago
[TECHNOLOGY] 2 sourcesWordPress admins hit by tampered CDN scripts for TrustPulse, OptinMonster, PushEngageA June 2026 CDN breach let attackers serve tampered JavaScript for TrustPulse, OptinMonster and PushEngage, creating hidden WordPress admin accounts and backdoors; only sites with logged‑in admins were affected
Sources
all-about-security.de · b2b-cyber-security.de · blogspan.net · borncity.com · brandspurng.com · cinemagia.wordpress.com · clubic.com · countryrebel.com · digitalmarketreports.com · es.wordpress.org · fishuniversity.com · flagthis.com · floranews.nl · gazeta-lokalna.pl · horizon3.ai · hvg.hu · it-administrator.de · it-boltwise.de · itnerd.blog · magazine-art.com · managerplus.pl · michael-bickel.de · news.co.za · pioneer.com · rbfirehose.com · rockyharbour.ca · sadio.org.ar · security-insider.de · security.nl · securityaffairs.co · spip-contrib.net · stranotizie.it · tele.org · telepolis.pl · thehackernews.com · vat.pravda.sk · wasi0013.com · youcangetitdone.com