New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

Updated July 18 2026 the two flaws now carry CVE IDs the full mechanism has been published a persistentobjectcache condition has surfaced and a working proofofconcept is public The story below reflects all of it An anonymous HTTP request can run code on a WordPress site The bug is in core so a bare install with zero plugins is exploitable Every 69 and 70 site was in range until