If you run a WordPress site, the advice this week is blunt: update it now. Two flaws in the software are under active exploitation across the internet.

WordPress powers more than half of every website online, so the blast radius is huge. Security firms say the attacks began within hours of the fix. An AI model sits on both sides of the story.

What wp2shell is

WordPress shipped the patches on Friday, in versions 7.0.2 and 6.9.5. It switched on forced auto-updates because of the risk. Researchers call the flaw wp2shell.

It combines two bugs. One is a SQL injection issue. The other, rated critical at 9.8 out of 10 by TechRadar, is a route confusion bug in the REST API that lets a request skip authentication. Apart, they are fiddly. Chained, they hand an anonymous attacker full remote control.