Blog
Insights on software development, security, and technology from our team.

One POST request now owns a default WordPress site. Patch to 7.0.2 today.
WordPress just patched wp2shell, an unauthenticated remote-code-execution chain in core that turns one crafted request into a full site takeover on a default install. It affects versions 6.8 through 7.0.1, and public exploit code is already circulating. Here's what web and security teams should do this week, and how to check if you were already hit.