Critical flaws wp2shell + xss2shellTest my site
01 / 15

Your new cyber auditor

Continuous offensive auditing of your external surface.

  • Compatible with NIST 2 / ISO 27001
  • Built and hosted in Paris
  • Powered by Mistral AI

Scroll, or use the arrow keys

Client cases

Two distinct clients, the same stakes

MSSP

French multicloud operator

Supports its clients through their IT transformation.

Continuous monitoring of client infrastructure, white-label scans.

FIRST SCAN
2critical
3high
  • Remote code execution on a WordPress instance (wp2shell)

    Compromise of a hosted client environment

  • Exposed database credentials

    Alteration or destruction of business data

END CLIENT

Employee benefits broker

Advisory in health, protection, retirement and employee savings.

Mapping of outsourced services, external and internal perimeter scans.

FIRST SCAN
1critical
2high
  • Administration console reachable without authentication

    Anonymous takeover of the business application, from development to production

  • XSS on the policyholder portal

    Silent exfiltration of login credentials

Anatomy of a compromise

From one forgotten WordPress to full compromise.

Discovery

41 exposed subdomains

Passive enumeration from the domain name alone, with no authentication and no agent

Identification

An unmaintained WordPress on blog.hosted-client.com

Fingerprinting of the technologies and versions running on each asset

Exploitation

Remote code execution confirmed

CVE-2026-63030, unauthenticated file upload, exploitation replayed

Impact

Write access to the business database

wp-config.php read, connection credentials stored in cleartext

From building the PoC to the alert in a few hours

Lessons from wp2shell, a critical vulnerability affecting WordPress

  1. Fri. 17 Jul. 2026WordPress

    wp2shell disclosed and patches published

  2. Same dayFlawfence

    Detection module developed and rolled out automatically

  3. + 1 hFlawfence

    First vulnerable instances detected

  4. Fri. to Sat. nightGitHub

    Working exploit code goes public

  5. Sat. morningFlawfence

    Exploit replayed and wired into the scan

  6. Sat. morning +1hFlawfence

    Findings confirmed and alerts sent

A snapshot, at the price of monitoring

The report already describes a system that changed.

3 months

from scoping to debrief

€20k

per audit

1 / year

and eleven months without visibility

They exploit faster than you patch

31%

of initial access starts with an exploited vulnerability

Verizon DBIR 2026, over 22,000 breaches analyzed. The leading initial access vector, ahead of stolen credentials, against 20% a year earlier.

43 days

to remediate an actively exploited vulnerability

Verizon DBIR 2026, median time to fix a flaw listed in CISA’s KEV catalog. It was 32 days a year earlier.

$4.99M

average cost of a data breach

IBM Cost of a Data Breach 2026, 602 organizations, March 2025 to February 2026. Global average, up 12% in one year.

Your inventory is not your perimeter

  • A staging environment opened for a demo
  • A test subdomain nobody shut down
  • A partner service still pointing at you

An auditor that never sleeps

A work email, and nothing to install.

  • The perimeter rebuilds itself
  • First report in under 24 hours
  • The scanning never stops

Four links, replayed on a loop

01

Map

A staging subdomain spotted in a certificate, missing from the inventory.

  • DNS
  • OSINT
  • WHOIS
02

Identify

A Swagger left public, describing the API and its internal routes.

  • Banner grabbing
  • Nuclei
  • Httpx
03

Exploit

A SQL injection confirmed by the data it returns.

  • Fuzzing
  • Agentic
  • DAST
04

Alert

A critical finding pushed to Slack the night it appears.

  • CVSS v4
  • NIST 2
  • SIEM

Proof of exploitation on every finding

The PoC used, the extracted data, the command to replay the test.

  • No finding reported without confirmed exploitation
  • Your teams can replay the test before opening a ticket
Vulnerability list for a perimeter in Flawfence, with severity, status and date
Detail of a critical command injection: PoC used, extracted data and verification command

Two measurements, method included

+30%

more subdomains discovered

On tesla.com, subdomains with an active DNS A record.

+30%

more exploitable vulnerabilities

Anonymous scan in default configuration against the hackazon platform.

Bug bounty on YesWeHackSee the counter

One report for your teams, another for your board

  • NIST 2 compliant PDF report
  • Immediate alerts on critical findings
  • A security score tracked over time
  • Remediation prioritized by exploitability

French, from the team to the hosting

Mistral AI
Hosted in Paris, data stays in France
Mistral AI models for the analysis
NIST 2 and ISO 27001 compliant exports

An audit once a year, or continuously

The one-off audit

€20kper audit

The usual format, to be repeated from one year to the next.

  • Scoping, testing, debrief
  • A report dated the day of the tests

Flawfence

From €5,000excl. VAT per year

The perimeter rebuilds itself, and the scanning never stops.

  • Continuous offensive scanning
  • Proof of exploitation on every finding
  • Immediate alerts on critical findings
  • NIST 2 compliant reports

Pricing scales with the size of the perimeter to audit.

Let us look at your perimeter

A demo, no commitment.

Passive preview, no sign-up. It reads public sources about the domain you enter.