WP2Shell WordPress RCE: ModSecurity Protection

wp2shell

Malware.Expert – ModSecurity Rules now protect WordPress websites against active WP2Shell attacks. The protection blocks malicious author_exclude SQL injection requests used in the unauthenticated WordPress Remote Code Execution exploit chain. The virtual patch was released on July 18, 2026, in Malware Expert ModSecurity Rules version 1.2026.12. What is WP2Shell? WP2Shell is a critical vulnerability chain … Read more

SQL Injection Vulnerability in NextGEN Gallery for WordPress

A WordPress NextGEN Gallery plugin installed on over one million sites has just fixed a severe SQL injection vulnerability that can allow attackers to steal data from a website’s database. Technical Details Vulnerability can be exploited by attackers in at least two different scenarios: First scenario The first attack scenario can happen if a WordPress … Read more

Content Injection Vulnerability in WordPress 4.7.x API

A new dangerous content injection vulnerability has been discovered in the WordPress CMS, it is a zero-day content injection flaw in the WordPress REST API. A fix for this was silently included on version 4.7.2 along with other less severe issues. Introduction This privilege escalation vulnerability affects the WordPress REST API that was recently added … Read more