WordPress Security Roundup — Core Unauthenticated RCE 'wp2shell' and a Wave of Admin Account Takeovers (July 2026)
In July 2026, an unauthenticated remote code execution flaw (wp2shell) was found in WordPress core, prompting an emergency patch, while a string of vulnerabilities that hand over entire admin accounts were disclosed in popular plugins. Here are the key facts and what to do.