Services
CMS Updates
Library Updates
Account
BLOGSEM Devs
Articles on software development, web and technology
WP2Shell: the WordPress flaw that needs no login
On 17 July WordPress closed WP2Shell, a two-CVE chain giving unauthenticated code execution on a clean install, and the first attempts landed within hours. What we checked across the sites we maintain, and why patched does not mean clean.