A single unauthenticated request chains into a full WordPress admin takeover: batch desync, unescaped SQL injection, then a brand new administrator account on any site running 6.9.0 to 7.0.1. The exploit was so tangled an AI reportedly pieced it together in 10 hours, and live sites were compromised within days. Here’s exactly how it works, and why you need to be on 7.0.2.
🔗 Relevant Links
https://github.com/Icex0/wp2shell-poc
https://techcrunch.com/2026/07/20/hackers-are-exploiting-recently-patched-wordpress-bugs-putting-millions-of-websites-at-risk/
❤️ More about us
Radically better observability stack: https://betterstack.com/
Written tutorials: https://betterstack.com/community/
Example projects: https://github.com/BetterStackHQ
📱 Socials
Twitter: https://twitter.com/betterstackhq
Instagram: https://www.instagram.com/betterstackhq/
TikTok: https://www.tiktok.com/@betterstack
LinkedIn: https://www.linkedin.com/company/betterstack
📌 Chapters:
0:00 WordPress has a hacking problem
0:25 Full admin access, live
0:53 How the exploit chain works
2:39 Running it on a stock install
3:36 Logged in as someone else’s admin
3:53 AI found this in 10 hours
4:23 How to protect yourself

コメント