WP2Shell WordPress RCE: ModSecurity Protection

wp2shell

Malware.Expert – ModSecurity Rules now protect WordPress websites against active WP2Shell attacks. The protection blocks malicious author_exclude SQL injection requests used in the unauthenticated WordPress Remote Code Execution exploit chain. The virtual patch was released on July 18, 2026, in Malware Expert ModSecurity Rules version 1.2026.12. What is WP2Shell? WP2Shell is a critical vulnerability chain … Read more

SQL Injection Vulnerability com_fields in Joomla 3.7

The vulnerability is caused by a new component, com_fields, which was introduced Joomla in version 3.7. If you use this version, you are affected and should update as soon as possible. This vulnerable component is publicly accessible, which means this issue can be exploited by any malicious individual visiting your site. Given the nature of … Read more

SQL Injection Vulnerability in NextGEN Gallery for WordPress

A WordPress NextGEN Gallery plugin installed on over one million sites has just fixed a severe SQL injection vulnerability that can allow attackers to steal data from a website’s database. Technical Details Vulnerability can be exploited by attackers in at least two different scenarios: First scenario The first attack scenario can happen if a WordPress … Read more