WordPress RCE chain mass exploitation explained

The wp2shell exploitation campaign is a useful case study in why chained vulnerabilities are disproportionately dangerous compared to isolated findings.
Two weaknesses in WordPress, neither carrying an individually alarming CVSS score, have been chained together to allow unauthenticated remote code execution followed by webshell deployment. Mass scanning activity is already underway, meaning exposed sites are being identified and compromised without any attacker needing valid credentials or prior access.
The broader point here matters beyond WordPress. In penetration testing, there's a tendency for scope and reporting to treat vulnerabilities as discrete items. But attackers don't work that way. A medium-severity misconfiguration combined with an information disclosure flaw can produce a critical outcome when they're used together. If your security assessments aren't actively exploring how findings chain together, you're likely getting an incomplete picture of your real exposure.
For any organisation running WordPress at scale, particularly where it sits in front of sensitive data or authenticated user flows, now is a reasonable moment to review plugin versions, validate patch status, and consider whether your last web application test covered exploit chaining as part of the methodology.
Concerned this affects you?
We can assess your exposure and tell you plainly where you stand.