WordPress Core "wp2shell" RCE flaws get public exploits, patch now

2026-07-18T19:23:25Z5cd515914687088e8078d2eb7a31a9cfa8939e3b684b9895096b7dc25f426da6
RCEabbottacr-stealeranthropicchrome-extensioncisaclicklockcoca-colacredential-theftdata-breachdenial-of-serviceernst-and-youngexploitfortinethollowbytelegacyhivemacosmalwareokobotopensslpatchingransomwarewindows-zero-daywordpresswp2shell

What happened

Multiple high-impact security events reported: public exploits released for the critical WordPress Core "wp2shell" RCE (administrators urged to patch immediately); CISA ordered priority remediation for actively exploited Fortinet FortiSandbox vulnerabilities; and a new Windows zero‑day (LegacyHive) enables local privilege escalation on up-to-date systems. Other notable incidents include an OpenSSL 11‑byte DoS (HollowByte), a surge in ACR Stealer credential‑theft attacks targeting enterprise customers, macOS ClickLock credential‑harvesting malware, a Chrome extension flaw in Anthropic’s Claude,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
5cd515914687088e8078d2eb7a31a9cfa8939e3b684b9895096b7dc25f426da6
Enrichment time
2026-07-18T19:23:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · WordPress Core "wp2shell" RCE flaws get public exploits, patch now · Baitaphish