Skip to content

Wordfence vulnerabilities

Wordfence features prominently in recent reporting on critical security developments in the WordPress ecosystem. The main event is the disclosure of 'wp2shell', the first critical unauthenticated WordPress Core RCE chain in nearly a decade, which was patched on July 17. Additionally, their autonomous AI researcher, PRISM, has become their top vulnerability researcher, detecting a backdoor in a plugin with 20,000 active installations within two hours of its introduction. Defenders should prioritize reviewing the exploitation timeline for the WordPress Core RCE, ensure all systems are updated with the latest patches immediately, and stay vigilant against fast-moving threats detected by AI-driven intelligence.

This hub is built from skopnix's own reporting on Wordfence: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.