Researchers published details of wp2root, an exploit chain that begins with AssetNote’s wp2shell pre-auth remote code execution in WordPress core and escalates limited PHP execution into full native code execution and ultimately Linux root on hardened hosts. The chain reportedly abuses a long-standing PHP Serializable/unserialize use-after-free flaw to obtain arbitrary memory read, discover live process addresses, and assemble a self-resolving ROP chain that bypasses restrictions such as disable_functions.
The final stage uses the 2026 Linux local privilege escalation dubbed Copy Fail to gain root without modifying files on disk. According to the report, the exploit launches an in-memory helper through memfd and execveat, then abuses the kernel page cache and /usr/bin/su to complete a fileless privilege escalation. The authors described the chain as a realistic demonstration of post-exploitation tradecraft against WordPress/PHP environments and said AI materially accelerated development of the multi-stage exploit.

Get the actors, campaigns, and ATT&CK mapping behind it.
7 events from the most recent confirmed update back to the earliest known activity.
A Rapid7 Metasploit pull request proposed a non-destructive auxiliary scanner module to detect WordPress REST API Batch Route Confusion and blind SQL injection exposure associated with CVE-2026-63030 and a second referenced CVE. The module supports single-target and batch scanning, optional SQL injection timing confirmation, and an optional Cloudflare WAF bypass setting.
COLCERT issued alert AL – 20260805 - 109 describing a critical WordPress vulnerability referred to as the "wp2shell" chain. The available reference identifies WordPress as the affected product but does not provide CVE, affected versions, or mitigation details.
Calif published "The WordPress Chain Massacre," detailing the wp2root post-exploitation chain from WordPress compromise through PHP escape to Linux root and framing it as a realistic hardened-host tradecraft demonstration.
The final stage invokes the 2026 Linux local privilege escalation dubbed "Copy Fail," using an in-memory helper executed via memfd and execveat to overwrite the page-cache copy of /usr/bin/su and obtain root without changing the on-disk binary.
Using leaked live code pointers and runtime parsing of the loaded PHP image, the exploit builds a self-resolving ROP chain, pivots execution through corrupted array bookkeeping, and launches position-independent shellcode.
The exploit chain uses an old PHP legacy Serializable/unserialize use-after-free bug to turn constrained PHP execution into arbitrary memory read, recover live addresses, and bypass restrictions such as disable_functions.
The referenced chain starts from AssetNote's "wp2shell," described as a pre-auth WordPress core remote code execution path that can let an unauthenticated attacker execute PHP code and create an administrator for plugin upload.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
11 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcecyberveille.ch
Open sourcemalware.news
Open sourceblog.calif.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcebtcirt.bt
Open sourcegovcert.bg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.