
Ryan Dewhurst
3.7K posts

Ryan Dewhurst
@ethicalhack3r
• Vulnerability & Threat Intelligence at https://t.co/hpcaDY39hO • Founder of @_WPScan_ (acquired by Automattic) • Founder of DVWA • Ethical Hacking Graduate
Katılım Haziran 2009
819 Takip Edilen21.2K Takipçiler


@caseyjohnellis Until a Supply Chain Attack comes and spoils the party 😅
English

@WifiRumHam @ethicalhack3r There's no poc. It just reveals the version; it's not that significant of a vulnerability.
English

@TheHackersNews Takes a little more than a single request. But yea, this is bad.
Luckily WordPress has had auto-updates enabled by default for a while. But there will still be many with auto-updates disabled.
English

🛑 URGENT - A single anonymous HTTP request can run code on an unpatched #WordPress 6.9 or 7.0 site, even on a default install with zero plugins.
The new wp2shell flaw sits in core and still has no CVE for scanners to match.
Affected releases and mitigations 🠖 thehackernews.com/2026/07/new-wp…

English

Curious to see who will be the first "Mythos" level AI-Powered Code Scanning tool to reverse-engineer the Remote Code Execution and construct a valid POC🍿
WordPress@WordPress
WordPress 7.0.2 is now available. This security release addresses 1 critical and 1 high severity issue, including a REST API vulnerability that could lead to remote code execution. Update your sites now. wp.me/pZhYe-5vp
English

WordPress has auto-updates enabled for security releases since a long time.
So hopefully this lowers blast radius significantly.
But there'll still be a lot out there with auto-updates disabled.
Ryan Dewhurst@ethicalhack3r
Reproducing wp2shell is trivial with AI. Buckle up!
English
Ryan Dewhurst retweetledi

WordPress 7.0.2 is now available. This security release addresses 1 critical and 1 high severity issue, including a REST API vulnerability that could lead to remote code execution. Update your sites now. wp.me/pZhYe-5vp
English
Ryan Dewhurst retweetledi

CVE-2026-46442 is hitting KEVIntel’s Flowise sensor.
First seen July 13, with attempts increasing: 20 from 7 attacker IPs.
The odd part? It’s an authenticated RCE, but attackers are running the exploit unauthenticated.
Now in our KEV Feed:
kevintel.com/CVE-2026-46442

English
Ryan Dewhurst retweetledi

The mystery is solved, maybe?
reddit.com/r/selfhosted/c…
Ryan Dewhurst@ethicalhack3r
Anyone want to help this guy escape from Belarus? 😬 Captured by KEVIntel sensors.
English

The mystery is solved, maybe?
reddit.com/r/selfhosted/c…
English
Ryan Dewhurst retweetledi
Ryan Dewhurst retweetledi

@ex_raritas They included an email address.
YOLO'ed and sent an email.
Let's see if they respond. Interested in true motivation.
English







