SECURITY·중요도 8·2026. 07. 17.·The Hacker News
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
── KO ──────────────────
워드프레스의 코어 결함으로 인증되지 않은 공격자가 코드 실행 가능.
워드프레스의 새로운 wp2shell 결함으로 인해 인증되지 않은 HTTP 요청으로 코드 실행이 가능하다. 이 버그는 코어에 존재하여 플러그인이 없는 기본 설치에서도 악용될 수 있다. 6.9 및 7.0 버전의 사이트가 영향을 받다가, 워드프레스는 6.9.5 및 7.0.2 버전을 출시하고 자동 업데이트 시스템을 통해 강제 업데이트 기능을 활성화했다.
── EN ──────────────────
A core flaw in WordPress allows unauthenticated attackers to run code.
A new core flaw in WordPress, known as wp2shell, allows unauthenticated HTTP requests to run code on a website. This bug exists in the core, making even a bare installation with no plugins exploitable. Versions 6.9 and 7.0 were affected until WordPress released updates 6.9.5 and 7.0.2, enabling forced updates via its auto-update system.