wp2shell (wordpress unauthenticated SQLi -> RCE) was first shared publicly about 2 days back.
Yesterday, we saw first signs of the SQLi being exploited on a honeypot. Today, the RCE was exploited too and the attacker used it to install a crypto miner and c2 client on the server.
wp2shell (wordpress unauthenticated SQLi -> RCE) was first shared publicly about 2 days back.
Yesterday, we saw first signs of the SQLi being exploited on a honeypot. Today, the RCE was exploited too and the attacker used it to install a crypto miner and c2 client on the server.