Daily Security Intel

Archives
Log in
Subscribe
July 19, 2026

[SecurityIntel] 19 Jul | Public Exploits Released For WordPress wp2shell RCE

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Sunday, July 19, 2026

INTEL CONFIDENCE  94%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Public Exploits Released For WordPress wp2shell RCE

CRITICAL

5

C2 IPs

40

OTX IOCs

4

ARTICLES

■ ANALYST TLDR

Today's threat landscape is dominated by active exploitation risks, highlighted by the release of public exploits for critical "wp2shell" remote code execution vulnerabilities in WordPress Core and a newly patched RCE flaw in 7-Zip. Additionally, Microsoft has warned of a significant surge in ACR Stealer malware campaigns actively targeting enterprise customers to harvest passwords, session tokens, and sensitive documents. Organizations must prioritize immediate patching of web infrastructure and archiving utilities while hardening endpoints against credential theft.

■ CRITICAL STORIES

CRITICAL#1

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

Public exploits are now available for critical remote code execution vulnerabilities in WordPress Core, significantly increasing the risk of automated site takeovers and web shell deployments.

HIGH#2

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

A remote code execution vulnerability in 7-Zip (fixed in v26.02) allows attackers to execute arbitrary code if a user is tricked into opening a specially crafted archive, posing a high risk for phishing and social engineering campaigns.

HIGH#3

Microsoft warns of surge in ACR Stealer attacks on customers

A spike in ACR Stealer malware activity threatens enterprise environments by actively exfiltrating browser-stored credentials, authentication tokens, and sensitive files.

■ CVEs IDENTIFIED

[CVE-TBD] (WordPress wp2shell)

WordPress Core — Remote Code Execution via wp2shell exploit

Critical

[CVE-TBD] (7-Zip RCE)

7-Zip (versions prior to 26.02) — Remote Code Execution via malicious archives

Critical

■ THREAT ACTORS

ACR Stealer Operators

Cybercrime / Info-stealer Group

Targeting Microsoft enterprise customers to steal passwords, tokens, and documents

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Public exploits released for WordPress Core wp2shell RCE vulnerabilities
T1203
Exploitation for Client Execution | Attackers exploiting 7-Zip RCE via malicious archives
T1555.003
Credentials from Web Browsers | ACR Stealer stealing browser-stored passwords
T1539
Steal Web Session Information | ACR Stealer harvesting authentication tokens from browsers
T1567
Exfiltration Over Web Service | ACR Stealer exfiltrating sensitive documents and credentials

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

WordPress Core — Public exploits are available for critical "wp2shell" RCE vulnerabilities — [BC] WordPress Core "wp2shell" RCE flaws get public exploits, patch now

[P1 PATCH NOW]≤24h

7-Zip (versions prior to 26.02) — Remote code execution vulnerability exploitable via malicious archives — [BC] Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately update all WordPress Core installations to the latest patched version to mitigate the "wp2shell" RCE vulnerabilities now actively targeted with public exploits.
2[P1] Upgrade all 7-Zip installations across the enterprise to version 26.02 or higher to remediate the [CVE-TBD] remote code execution flaw.
3[P2] Deploy endpoint detection rules to identify ACR Stealer execution, specifically monitoring unauthorized access to browser credential stores and sensitive document directories.
4[P2] Implement email filtering rules to block or inspect incoming archive files (e.g., .zip, .7z) from external sources to prevent exploitation of the 7-Zip RCE vulnerability.
5[P3] Review and invalidate active enterprise session tokens if anomalous credential access or ACR Stealer activity is detected on host endpoints.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 20 Jul | SonicWall VPN Zero-Days and Critical NGINX RCE Older → [SecurityIntel] 18 Jul | Unauthenticated WordPress Core wp2shell RCE Threatens Millions
Powered by Buttondown, the easiest way to start and grow your newsletter.