Mark RadarMARK RADAR
EN
Event File AI

Hackers Exploit WordPress wp2shell Flaw to Steal Admin Credentials

1 reports · First detected 2026-07-22 · Last active 2026-07-22

The critical wp2shell vulnerability chain affects WordPress installations and could allow attackers to compromise administrative systems, putting website operations and sensitive data at risk. The flaw was initially identified by a security research organization using OpenAI’s GPT 5.6 Sol artificial-intelligence model, underscoring the growing role of AI tools in vulnerability discovery and defensive cybersecurity research.

As of July 22, 2026, proof-of-concept code for wp2shell had surfaced and hackers were exploiting the vulnerability in active attacks. The attackers uploaded malicious plugins to establish persistent backdoors, harvested administrator accounts and credentials, and gained continued access to WordPress dashboards. Reports did not disclose the number of affected websites, estimated financial losses or the share of installations that had applied available protections.

All Coverage

1 original reports

The Backstory

The history behind this event
Researchers Use GPT-5.6 to Uncover Major WordPress Flaw2026-07-22 · 2 reports · similarity 0.82

WordPress underpins a large share of the world’s websites, making flaws in its software a potentially broad security risk. Researchers at Searchlight Cyber used OpenAI’s GPT-5.6 Sol Ultra to examine source code and test whether generative AI could automate vulnerability discovery and connect weaknesses into a workable exploitation chain. The experiment highlights how advanced models may sharply reduce the time and cost required for offensive security research.

The Searchlight Cyber team identified the major WordPress vulnerability, dubbed wp2shell, in about 10 hours using the AI model. A cybersecurity report published on July 22, 2026, said attackers were actively exploiting the flaw, adding urgency beyond the initial research demonstration. The timeline underscores both the efficiency of AI-assisted vulnerability hunting and the shrinking window for website operators to assess exposure, apply available updates and strengthen defenses.

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)