The WordPress security team has issued an urgent call for administrators to immediately update their sites, following the public release of exploit code for two critical remote code execution (RCE) vulnerabilities in the core software. The flaws, collectively dubbed "wp2shell," allow a low-privileged attacker to take complete control of a website.

According to a report by BleepingComputer, the danger escalated significantly when proof-of-concept exploits became publicly available. This transforms a theoretical security risk into an immediate threat, with automated attack campaigns now anticipated to target unpatched WordPress installations across the internet.

The vulnerability chain is particularly severe. It combines two distinct flaws: a directory traversal bug and a deserialization flaw. When chained together by an authenticated attacker—even one with only subscriber-level permissions—they can achieve full remote code execution, leading to complete site takeover. The technical barrier for exploitation has been dramatically lowered by the public release of these working exploits.

In response, WordPress has released patches in versions 6.6.2 and 6.5.4. Site administrators are strongly advised to perform a full backup before applying the update. For organizations managing multiple WordPress sites, the use of centralized patch management tools is recommended to ensure consistent and swift deployment of the security fix across their entire portfolio.

For sites where an immediate update is not feasible, the WordPress security team has provided emergency mitigation rules as a temporary stopgap to block attack vectors until a full patch can be applied.

This incident serves as a stark case study in the dual-edged nature of public vulnerability disclosure within open-source projects. While transparency is a cornerstone that enables rapid community validation and patch development, it simultaneously provides malicious actors with ready-made attack tools. In this scenario, the release of public exploits has turned a patched vulnerability into a race against time for any administrator who has fallen behind on updates, underscoring the critical need for proactive and disciplined patch management in today's threat landscape.


WordPress 安全團隊緊急呼籲管理員立即更新網站,因核心軟件中的兩個關鍵遠端代碼執行(RCE)漏洞的攻擊代碼已公開發布。這些被統稱為「wp2shell」的漏洞,允許低權限攻擊者完全控制網站。

據 BleepingComputer 報導,當概念驗證攻擊代碼公開可用後,危險性顯著提升。這將理論上的安全風險轉化為即時威脅,預計將有自動化攻擊活動針對互聯網上未修補的 WordPress 安裝。

該漏洞鏈尤為嚴重。它結合了兩個不同的缺陷:一個目錄遍歷漏洞和一個反序列化漏洞。當被認證的攻擊者——即使僅擁有訂閱者級別權限——將兩者結合時,便可實現完整的遠端代碼執行,從而完全接管網站。這些可用攻擊代碼的公開發布,大幅降低了利用漏洞的技術門檻。

作為回應,WordPress 已在 6.6.2 和 6.5.4 版本中發布了補丁。強烈建議網站管理員在應用更新前進行完整備份。對於管理多個 WordPress 網站的組織,建議使用集中的補丁管理工具,以確保安全修補程式在其整個產品組合中快速且一致地部署。

對於無法立即更新的網站,WordPress 安全團隊提供了緊急緩解規則作為臨時權宜之計,以在完整補丁應用前阻斷攻擊向量。

此事件清晰地展示了開源項目中公開漏洞披露的雙刃劍性質。雖然透明度是實現快速社區驗證和補丁開發的基石,但它同時也為惡意行為者提供了現成的攻擊工具。在這種情況下,公開攻擊代碼的發布,使一個已修補的漏洞對於任何更新滯後的管理員來說,都變成了與時間的賽跑,凸顯了在當今威脅環境中,主動且嚴格的補丁管理至關重要。

新聞來源 / Original News Source