So, we are apparently not vulnerable to this specific CVE since we have
the "No-User-Account Booking Mode" disabled.
HOWEVER(!), we seem to have a much bigger problem. There are dozens of
unathorized admin users that were added in the last 5 days:
| 9530 | wpsvc_e12136bfb294 | wpsvc_e12136bfb294(a)wordpress-svc.internal | 2026-07-19
04:04:00 |
| 9531 | wpsvc_07c3640f82d0 | wpsvc_07c3640f82d0(a)wordpress-svc.internal | 2026-07-19
05:39:34 |
| 9532 | wpenginebot | wpenginebot(a)wpengine.com | 2026-07-20
15:20:35 |
| 9533 | site_admin | site_admin(a)wp2shell.invalid | 2026-07-21
08:35:01 |
| 9534 | wp2_8ae50e | wp2_8ae50e(a)wp2shell.invalid | 2026-07-21
10:01:20 |
| 9535 | wpadmin-test | wpadmin-test(a)wp2shell.invalid | 2026-07-22
02:15:46 |
| 9536 | wpsvc_dbd338819964 | wpsvc_dbd338819964(a)wordpress-svc.internal | 2026-07-22
03:39:11 |
| 9537 | wpsvc_c941bd362884 | wpsvc_c941bd362884(a)wordpress-svc.internal | 2026-07-23
02:26:14 |
| 9538 | w2s_9a6b2e668f36 | w2s_9a6b2e668f36(a)wp2shell.local | 2026-07-23
10:47:10 |
| 9539 | w2s_4faa0aaf20be | w2s_4faa0aaf20be(a)wp2shell.local | 2026-07-23
11:10:57 |
| 9540 | w2s_6f9e17f48ff2 | w2s_6f9e17f48ff2(a)wp2shell.local | 2026-07-23
11:57:18 |
| 9541 | cacheopsb844a0 | cacheopsb844a0(a)mailinator.com | 2026-07-23
15:43:21 |
| 9542 | w2s_be007913f621 | w2s_be007913f621(a)wp2shell.local | 2026-07-23
15:51:54 |
| 9543 | w2s_40e0767305ce | w2s_40e0767305ce(a)wp2shell.local | 2026-07-23
16:54:12 |
| 9544 | w2s_9eafb7d74346 | w2s_9eafb7d74346(a)wp2shell.local | 2026-07-23
18:51:47 |
| 9545 | w2s_5dfee33af93a | w2s_5dfee33af93a(a)wp2shell.local | 2026-07-23
19:56:04 |
| 9546 | w2s_5d87bef0d4ea | w2s_5d87bef0d4ea(a)wp2shell.local | 2026-07-23
23:02:17 |
| 9547 | w2s_483e11621b36 | w2s_483e11621b36(a)wp2shell.local | 2026-07-24
00:25:03 |
| 9548 | w2s_a9bb131f2517 | w2s_a9bb131f2517(a)wp2shell.local | 2026-07-24
02:04:08 |
| 9549 | w2s_a356b96de96a | w2s_a356b96de96a(a)wp2shell.local | 2026-07-24
03:51:41 |
| 9550 | w2s_178b0c2ae79a | w2s_178b0c2ae79a(a)wp2shell.local | 2026-07-24
04:16:23 |
| 9551 | cacheops838874 | cacheops838874(a)mailinator.com | 2026-07-24
04:20:00 |
| 9552 | w2s_2aa400527cde | w2s_2aa400527cde(a)wp2shell.local | 2026-07-24
14:40:39 |
| 9553 | wp_admin_a6bb6a | wp_admin_a6bb6a(a)local.host | 2026-07-24
14:46:36 |
| 9554 | w2s_a4209448783d | w2s_a4209448783d(a)wp2shell.local | 2026-07-24
16:18:23 |
| 9555 | w2s_a1a88d354787 | w2s_a1a88d354787(a)wp2shell.local | 2026-07-24
17:16:57 |
| 9556 | w2s_cab74ca7c399 | w2s_cab74ca7c399(a)wp2shell.local | 2026-07-24
17:52:00 |
| 9557 | w2s_8738e1cb0ab5 | w2s_8738e1cb0ab5(a)wp2shell.local | 2026-07-25
03:38:56 |
| 9558 | wp_admin_2c903b | wp_admin_2c903b(a)local.host | 2026-07-25
04:16:10 |
| 9559 | w2s_0a3c1ca4e550 | w2s_0a3c1ca4e550(a)wp2shell.local | 2026-07-25
04:21:29 |
| 9560 | bob_63bcc59e228e | bob_63bcc59e228e(a)bobresearchlabs.com | 2026-07-25
05:18:37 |
Based on the "wp2shell" identifiers, this seems to be a recently
published exploit:
I'm working on blocking and remediation right now. More to follow.
--Sean
On Thu, Jul 23, 2026 at 10:57:21PM -0700, Jake via sudo-sys wrote:
---------- Forwarded message ----------
Date: Fri, 24 Jul 2026 05:11:31 +0000
From: Evan Harris via Info <info(a)sudoroom.org>
Reply-To: Evan Harris <security(a)mail.mcpsec.dev>
To: info(a)sudoroom.org
Subject: [sudo-info] Security notice: Events Manager plugin update recommended
on
sudoroom.org
Hi there,
I'm reaching out about a possible security issue affecting your website.
Your site runs the WordPress plugin Events Manager, version 7.2.3.1 (read from the
plugin's public readme.txt). That release is within the affected range of the issue
below (fixed in 7.3.7). Whether your site is actually exposed depends on a setting we
cannot see: this flaw is only exploitable when Events Manager accepts bookings without
requiring a user account ("No-User-Account Booking Mode"). If you accept public
bookings that way, please update to 7.3.7 or later.
The specific issue affecting that version range:
- CVE-2026-12987: an unauthenticated PHP object injection leading to SQL injection: on
sites using No-User-Account Booking Mode, a booker-supplied registration field is stored
as booking meta and later deserialized without restricting allowed classes, and the
resulting object-injection chain reaches an unparameterised database query — so an
unauthenticated attacker can read arbitrary database data such as password hashes and
secret keys (affected: Events Manager 4.0.0 through 7.3.6, fixed in 7.3.7 — only
exploitable on sites using No-User-Account Booking Mode).
The fix is to update Events Manager to version 7.3.7 or later; the write-up below walks
through how to check your version and upgrade safely.
One important qualifier, so this isn't over-stated: whether your site is actually
exposed depends on a setting we cannot see. This issue is only exploitable when Events
Manager is configured for "No-User-Account Booking Mode" — i.e. it accepts
bookings from visitors who are not logged in. We can read your plugin version but not your
booking configuration, so this is a precautionary heads-up, not a confirmed finding for
your site, and we have no indication it is being exploited. If you do accept public
bookings without requiring an account, please treat updating to 7.3.7 or later as a
priority; because the underlying flaw could expose database contents such as password
hashes and secret keys, rotating those secrets after updating would be a sensible
precaution in that case. We did not access your site, your database, or the booking flow,
and we did not test or exploit anything.
You can verify all of this independently, from sources that aren't me:
- The plugin on the
WordPress.org directory, and its current version:
https://wordpress.org/plugins/events-manager/
- CVE-2026-12987 at the US National Vulnerability Database:
https://nvd.nist.gov/vuln/detail/CVE-2026-12987
- My own write-up, with how to check your version and upgrade safely:
https://mcpsec.dev/events-security/
To be clear about what I did: I only looked at files your site already serves to every
visitor (the Events Manager plugin's public readme.txt, and your homepage), the same
way your homepage is public. I did not access your WordPress admin area, your database, or
any private part of the site. In particular, I did not touch the vulnerable booking path,
and I did not test or exploit anything. This is a version-based observation, and — because
this issue is config-dependent — a site in the affected range may not be exposed at all.
If you're not the person who maintains the site, please forward this to whoever does.
I'm happy to help if you have any questions.
Best,
Evan
Security Researcher at mcpsec.dev
This is a good-faith security notification intended for the operator of the website
referenced above. If you are not the right person, or received this in error, please reply
to let us know and we will update our records, or simply disregard this message.
NOTE: emails to the Info list were sent to an individual email address (such as
info(a)sudoroom.org) with the PRESUMPTION OF PRIVACY. They may include personal information
which the sender would not have sent to a public list (such as sudo-discuss). If you must
forward messages to a public list, please take great care to REMOVE SENSITIVE INFORMATION!
_______________________________________________
Info mailing list -- info(a)sudoroom.org
To unsubscribe send an email to info-leave(a)sudoroom.org
_______________________________________________
sudo-sys mailing list -- sudo-sys(a)sudoroom.org
To unsubscribe send an email to sudo-sys-leave(a)sudoroom.org
More options at
https://sudoroom.org/lists/postorius/lists/sudo-sys.sudoroom.org/