omg thank you Sean you're saving us!!!
On Sat, 25 Jul 2026, Sean Greenslade via sudo-sys wrote:
On Sat, Jul 25, 2026 at 12:03:52AM -0700, Sean
Greenslade via sudo-sys wrote:
So, we are apparently not vulnerable to this
specific CVE since we have
the "No-User-Account Booking Mode" disabled.
HOWEVER(!), we seem to have a much bigger problem. There are dozens of
unathorized admin users that were added in the last 5 days:
| 9530 | wpsvc_e12136bfb294 | wpsvc_e12136bfb294(a)wordpress-svc.internal | 2026-07-19
04:04:00 |
| 9531 | wpsvc_07c3640f82d0 | wpsvc_07c3640f82d0(a)wordpress-svc.internal | 2026-07-19
05:39:34 |
| 9532 | wpenginebot | wpenginebot(a)wpengine.com | 2026-07-20
15:20:35 |
| 9533 | site_admin | site_admin(a)wp2shell.invalid | 2026-07-21
08:35:01 |
| 9534 | wp2_8ae50e | wp2_8ae50e(a)wp2shell.invalid | 2026-07-21
10:01:20 |
| 9535 | wpadmin-test | wpadmin-test(a)wp2shell.invalid | 2026-07-22
02:15:46 |
| 9536 | wpsvc_dbd338819964 | wpsvc_dbd338819964(a)wordpress-svc.internal | 2026-07-22
03:39:11 |
| 9537 | wpsvc_c941bd362884 | wpsvc_c941bd362884(a)wordpress-svc.internal | 2026-07-23
02:26:14 |
| 9538 | w2s_9a6b2e668f36 | w2s_9a6b2e668f36(a)wp2shell.local | 2026-07-23
10:47:10 |
| 9539 | w2s_4faa0aaf20be | w2s_4faa0aaf20be(a)wp2shell.local | 2026-07-23
11:10:57 |
| 9540 | w2s_6f9e17f48ff2 | w2s_6f9e17f48ff2(a)wp2shell.local | 2026-07-23
11:57:18 |
| 9541 | cacheopsb844a0 | cacheopsb844a0(a)mailinator.com | 2026-07-23
15:43:21 |
| 9542 | w2s_be007913f621 | w2s_be007913f621(a)wp2shell.local | 2026-07-23
15:51:54 |
| 9543 | w2s_40e0767305ce | w2s_40e0767305ce(a)wp2shell.local | 2026-07-23
16:54:12 |
| 9544 | w2s_9eafb7d74346 | w2s_9eafb7d74346(a)wp2shell.local | 2026-07-23
18:51:47 |
| 9545 | w2s_5dfee33af93a | w2s_5dfee33af93a(a)wp2shell.local | 2026-07-23
19:56:04 |
| 9546 | w2s_5d87bef0d4ea | w2s_5d87bef0d4ea(a)wp2shell.local | 2026-07-23
23:02:17 |
| 9547 | w2s_483e11621b36 | w2s_483e11621b36(a)wp2shell.local | 2026-07-24
00:25:03 |
| 9548 | w2s_a9bb131f2517 | w2s_a9bb131f2517(a)wp2shell.local | 2026-07-24
02:04:08 |
| 9549 | w2s_a356b96de96a | w2s_a356b96de96a(a)wp2shell.local | 2026-07-24
03:51:41 |
| 9550 | w2s_178b0c2ae79a | w2s_178b0c2ae79a(a)wp2shell.local | 2026-07-24
04:16:23 |
| 9551 | cacheops838874 | cacheops838874(a)mailinator.com | 2026-07-24
04:20:00 |
| 9552 | w2s_2aa400527cde | w2s_2aa400527cde(a)wp2shell.local | 2026-07-24
14:40:39 |
| 9553 | wp_admin_a6bb6a | wp_admin_a6bb6a(a)local.host | 2026-07-24
14:46:36 |
| 9554 | w2s_a4209448783d | w2s_a4209448783d(a)wp2shell.local | 2026-07-24
16:18:23 |
| 9555 | w2s_a1a88d354787 | w2s_a1a88d354787(a)wp2shell.local | 2026-07-24
17:16:57 |
| 9556 | w2s_cab74ca7c399 | w2s_cab74ca7c399(a)wp2shell.local | 2026-07-24
17:52:00 |
| 9557 | w2s_8738e1cb0ab5 | w2s_8738e1cb0ab5(a)wp2shell.local | 2026-07-25
03:38:56 |
| 9558 | wp_admin_2c903b | wp_admin_2c903b(a)local.host | 2026-07-25
04:16:10 |
| 9559 | w2s_0a3c1ca4e550 | w2s_0a3c1ca4e550(a)wp2shell.local | 2026-07-25
04:21:29 |
| 9560 | bob_63bcc59e228e | bob_63bcc59e228e(a)bobresearchlabs.com | 2026-07-25
05:18:37 |
Based on the "wp2shell" identifiers, this seems to be a recently
published exploit:
https://ddsystems.com/the-wordpress-wp2shell-vulnerability-what-happened-an…
I'm working on blocking and remediation right now. More to follow.
OK, I got some really basic Apache mitigations in place to block the
endpoints the wp2shell explot uses. Also went through and deleted all
the above listed rogue admin accounts. At least according to the WP
admin panel none of them ever logged in, so we maybe dodged the bullet
on this? I still need to review more logs and check over the rest of the
Wordpress install to make sure nothing got tampered with, but that can
wait. Sleep now.
--Sean
_______________________________________________
sudo-sys mailing list -- sudo-sys(a)sudoroom.org
To unsubscribe send an email to sudo-sys-leave(a)sudoroom.org
More options at
https://sudoroom.org/lists/postorius/lists/sudo-sys.sudoroom.org/