On Sat, Jul 25, 2026 at 12:03:52AM -0700, Sean Greenslade via sudo-sys wrote:
So, we are apparently not vulnerable to this specific
CVE since we have
the "No-User-Account Booking Mode" disabled.
HOWEVER(!), we seem to have a much bigger problem. There are dozens of
unathorized admin users that were added in the last 5 days:
| 9530 | wpsvc_e12136bfb294 | wpsvc_e12136bfb294(a)wordpress-svc.internal | 2026-07-19
04:04:00 |
| 9531 | wpsvc_07c3640f82d0 | wpsvc_07c3640f82d0(a)wordpress-svc.internal | 2026-07-19
05:39:34 |
| 9532 | wpenginebot | wpenginebot(a)wpengine.com | 2026-07-20
15:20:35 |
| 9533 | site_admin | site_admin(a)wp2shell.invalid | 2026-07-21
08:35:01 |
| 9534 | wp2_8ae50e | wp2_8ae50e(a)wp2shell.invalid | 2026-07-21
10:01:20 |
| 9535 | wpadmin-test | wpadmin-test(a)wp2shell.invalid | 2026-07-22
02:15:46 |
| 9536 | wpsvc_dbd338819964 | wpsvc_dbd338819964(a)wordpress-svc.internal | 2026-07-22
03:39:11 |
| 9537 | wpsvc_c941bd362884 | wpsvc_c941bd362884(a)wordpress-svc.internal | 2026-07-23
02:26:14 |
| 9538 | w2s_9a6b2e668f36 | w2s_9a6b2e668f36(a)wp2shell.local | 2026-07-23
10:47:10 |
| 9539 | w2s_4faa0aaf20be | w2s_4faa0aaf20be(a)wp2shell.local | 2026-07-23
11:10:57 |
| 9540 | w2s_6f9e17f48ff2 | w2s_6f9e17f48ff2(a)wp2shell.local | 2026-07-23
11:57:18 |
| 9541 | cacheopsb844a0 | cacheopsb844a0(a)mailinator.com | 2026-07-23
15:43:21 |
| 9542 | w2s_be007913f621 | w2s_be007913f621(a)wp2shell.local | 2026-07-23
15:51:54 |
| 9543 | w2s_40e0767305ce | w2s_40e0767305ce(a)wp2shell.local | 2026-07-23
16:54:12 |
| 9544 | w2s_9eafb7d74346 | w2s_9eafb7d74346(a)wp2shell.local | 2026-07-23
18:51:47 |
| 9545 | w2s_5dfee33af93a | w2s_5dfee33af93a(a)wp2shell.local | 2026-07-23
19:56:04 |
| 9546 | w2s_5d87bef0d4ea | w2s_5d87bef0d4ea(a)wp2shell.local | 2026-07-23
23:02:17 |
| 9547 | w2s_483e11621b36 | w2s_483e11621b36(a)wp2shell.local | 2026-07-24
00:25:03 |
| 9548 | w2s_a9bb131f2517 | w2s_a9bb131f2517(a)wp2shell.local | 2026-07-24
02:04:08 |
| 9549 | w2s_a356b96de96a | w2s_a356b96de96a(a)wp2shell.local | 2026-07-24
03:51:41 |
| 9550 | w2s_178b0c2ae79a | w2s_178b0c2ae79a(a)wp2shell.local | 2026-07-24
04:16:23 |
| 9551 | cacheops838874 | cacheops838874(a)mailinator.com | 2026-07-24
04:20:00 |
| 9552 | w2s_2aa400527cde | w2s_2aa400527cde(a)wp2shell.local | 2026-07-24
14:40:39 |
| 9553 | wp_admin_a6bb6a | wp_admin_a6bb6a(a)local.host | 2026-07-24
14:46:36 |
| 9554 | w2s_a4209448783d | w2s_a4209448783d(a)wp2shell.local | 2026-07-24
16:18:23 |
| 9555 | w2s_a1a88d354787 | w2s_a1a88d354787(a)wp2shell.local | 2026-07-24
17:16:57 |
| 9556 | w2s_cab74ca7c399 | w2s_cab74ca7c399(a)wp2shell.local | 2026-07-24
17:52:00 |
| 9557 | w2s_8738e1cb0ab5 | w2s_8738e1cb0ab5(a)wp2shell.local | 2026-07-25
03:38:56 |
| 9558 | wp_admin_2c903b | wp_admin_2c903b(a)local.host | 2026-07-25
04:16:10 |
| 9559 | w2s_0a3c1ca4e550 | w2s_0a3c1ca4e550(a)wp2shell.local | 2026-07-25
04:21:29 |
| 9560 | bob_63bcc59e228e | bob_63bcc59e228e(a)bobresearchlabs.com | 2026-07-25
05:18:37 |
Based on the "wp2shell" identifiers, this seems to be a recently
published exploit:
https://ddsystems.com/the-wordpress-wp2shell-vulnerability-what-happened-an…
I'm working on blocking and remediation right now. More to follow.
OK, I got some really basic Apache mitigations in place to block the
endpoints the wp2shell explot uses. Also went through and deleted all
the above listed rogue admin accounts. At least according to the WP
admin panel none of them ever logged in, so we maybe dodged the bullet
on this? I still need to review more logs and check over the rest of the
Wordpress install to make sure nothing got tampered with, but that can
wait. Sleep now.
--Sean