THE article discusses the `wp2shell` vulnerability in WordPress that enables pre-authentication remote code execution (RCE), disclosed by Searchlight Cyber on July 17, 2026. It details the attack chain, including detection techniques used with Elastic Defend, indicators of compromise (IOCs), and recommendations for patching WordPress to mitigate risks. Key aspects include:
1. **Vulnerability Overview**: Presents the nature of `wp2shell`, affected WordPress versions, and its exploitation method through the REST API.
2. **Detection Rules**: Lists specific detection rules in Elastic Defend to identify exploitation activities and the alerts generated during lab testing of the exploit.
3. **Field Intel**: Highlights the observed patterns in telemetry data from customer environments following the vulnerability disclosure, including the creation of suspicious plugin directories.
4. **Hunting Queries**: Provides guidance on using telemetry indicators and behavioral detection for active monitoring of potential exploits on WordPress sites.
5. **Recommendations**: Advises immediate patching to secure WordPress installations against the identified vulnerabilities.