Default WordPress Sites Can Be Taken Over Directly
WP2Shell breaks the usual WordPress assumption that only plugins or custom code create serious exposure. A default install can be reached without a login, then turned into code execution, new admin accounts, web shells, and database theft.
FortiGuard says exploitation is increasing after public technical details and proof-of-concept code appeared. The affected core versions are WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1, with fixes in 6.9.5, 7.0.2, or later.
The practical problem is persistence. A simple code patch does not remove a backdoor account or web shell that was already planted, so the compromise can outlast the vulnerability itself.