Critical flaws wp2shell + xss2shellTest my site
FLAWFENCE · BLOG

Offensive cybersecurity & AI

Analysis, guides and field experience by the Flawfence team on asset mapping, vulnerability scanning and information system security.

Data breachDGFiPPhishing

DGFiP data breach 2026: am I affected by the French tax leak?

DGFiP data breach: three intrusions in June, July and August 2026, 678,000 tax records stolen. Are you affected, and what to do against fraud?

69 min read
Read article
WordPressXSSRCE

xss2shell (CVE-2026-64638): wp2shell’s little sister, now exposing your WordPress

xss2shell (CVE-2026-64638) affects every version of WordPress before 7.0.3 and can lead to a full site takeover. What the flaw means for your organization, how to check your exposure and how to protect yourself.

18 min read
Read article
NIS2Resilience LawCompliance

France's Resilience Law (NIS2): what becomes mandatory, and 3 projects to start without waiting for the decrees

Where the French NIS2 transposition stands, who is in scope, what the law defers to ANSSI decrees, and the three projects you can start right now.

9 min read
Read article
EASMAttack surfaceShadow IT

External attack surface: how to inventory yours in 30 minutes

A step-by-step method to list what you expose on the internet: forgotten subdomains, Shadow IT, open ports, mail posture. With the commands and the free tools.

10 min read
Read article
PentestAuditBudget

How much does a security audit cost in 2026? A real pricing grid

What a pentest, a vulnerability scan and a full audit actually cost in 2026: market ranges, what moves a quote, and how to read one without getting burned.

10 min read
Read article
WordPressRCEVulnerability

wp2shell (CVE-2026-63030): The Unauthenticated RCE Hitting the Heart of WordPress

wp2shell is a pre-auth RCE in WordPress Core (CVE-2026-63030 + CVE-2026-60137). How it works, affected versions, PoC, detection and remediation.

12 min read
Read article
ISO 27001Vulnerability ScanCompliance

How to Automate Vulnerability Scanning for ISO 27001?

Control A.8.8, scan frequency, audit evidence: the practical guide to setting up automated vulnerability scanning that satisfies ISO 27001:2022.

6 min read
Read article
NIS2ComplianceAudit Report

How to Write a NIS2 Compliance Report (2026 Guide)

Report structure, Article 21 measures, technical evidence auditors expect: the complete guide to writing a clear, actionable NIS2 compliance report.

7 min read
Read article
MappingShadow IT

Why map your company's information system?

Mapping the IT infrastructure is a pillar of cybersecurity. Discover why and how to map your company's information system.

6 min read
Read article
Penetration TestPentestAudit

Which Vulnerability Scan to Use in 2026?

A guide to choosing the right vulnerability scanning tool in 2026

7 min read
Read article