Sam: Unauthenticated remote code execution on a default WordPress install. The exploit's already in the wild, and the only thing saving you is whether you happened to turn on a persistent object cache.
Kai: [excited] This is Kai.
Sam: And this is Sam.
Kai: It's July 22nd, 2026, and we've got three open-source stories that are gonna wreck your afternoon — in the best and worst ways.
Sam: [dry] Two of them are patch-now emergencies. Kai's excited about all three anyway.
Kai: First up — a WordPress chain called 'wp2shell,' exploited in the wild, with public proof-of-concept fueling mass scanning right now.
Sam: Then the one bit of good news: TypeScript 7.0 shipped stable. The Go-based compiler rewrite, eight to twelve times faster builds.
Kai: [excited] EIGHT to TWELVE X, Sam, I—
Sam: And a critical nginx heap overflow, CVSS 9.2, that can crash workers and maybe get you RCE. F5's got a patch.
Kai: Big day for the people who run literally the entire internet.
Kai: Okay, 'wp2shell.' Sam, walk me through it, because the name alone is terrifying.
Sam: It's two WordPress core bugs chained together. One's a REST API batch-route confusion, the other's a SQL injection that's been sitting there since 6.8.
Kai: Wait — since 6.8? That's been baked in for how long?
Sam: Long enough. And chained, they give you unauthenticated RCE on a default install. No login, no plugin, just core WordPress.
Kai: So what's the one weird trick that saves you? You mentioned caching in the cold open.
Sam: Per Cloudflare, the RCE only fully lands when you're NOT running a persistent object cache. So Redis and Memcached users kind of dodged the bullet by accident.
Kai: [laughs] So the fastest sites are the safest sites. Performance IS security.
Sam: [dry] Don't put that on a t-shirt. Most small blogs run no object cache at all — and that's the world's largest CMS ecosystem sitting wide open.
Kai: But there are fixes, right? Tell me there are fixes.
Sam: Yeah — 6.8.6, 6.9.5, and 7.0.2, with forced auto-updates. If auto-update's on, you may already be patched.
Kai: See? The system works! Everybody go touch grass.
Sam: [sighs] Except mass scanning started the second the PoC dropped. Attackers are racing the auto-updater. And if you disabled auto-updates 'for stability'—
Kai: —which is everyone's uncle with a WooCommerce store—
Sam: —you're the target. So check your version right now, force the update, and if you can't, get an object cache up as a stopgap.
Kai: Hot take: this is the defining WordPress incident of the year, and half the affected sites won't hear about it for a month.
Sam: That's not a hot take, that's just Tuesday. But yeah — if you were slow, assume compromise.
Kai: [excited] Okay, THIS is the one I've been vibrating about. TypeScript 7.0 shipped stable!
Sam: The Go rewrite. They finally did it — ending a decade of TypeScript written in TypeScript.
Kai: Full-build speedups of eight to TWELVE X, Sam. And VS Code type-checking went from a hundred twenty-five seconds to under eleven.
Sam: That number I actually believe, because Microsoft's shipping the benchmarks and the source. This isn't some startup's press release.
Kai: A hundred twenty-five seconds down to eleven! That's the difference between hating your job and—
Sam: —and still hating your job, but faster. There's a catch, Kai. There's always a catch.
Kai: [sighs] Fine. What's the catch.
Sam: Vue, Svelte, Astro, MDX — those folks have to wait for 7.1. The plugin API for custom file types isn't ready yet.
Kai: Okay, but that's a huge chunk of the frontend world just... sitting this one out.
Sam: Right. So don't rip out your toolchain on a Friday because a blog post got you excited.
Kai: [laughs] That is a direct attack and I will not stand for it.
Sam: So if you're a plain TS or React shop, try it in CI this week and measure your own numbers. If you're Vue or Svelte, hang tight for 7.1.
Kai: My hot take? A native compiler for a language this big is the biggest dev-tooling moment since Rust ate the build-tools world.
Sam: [beat] That's... actually not a bad take. Broken clock.
Kai: I'm framing that.
Sam: Back to bad news. Critical nginx flaw, CVE-2026-42533, CVSS 9.2.
Kai: nginx? As in the thing in front of, like, half the world's web traffic?
Sam: That one. F5 patched a heap buffer overflow in NGINX Plus and Open Source. Unauthenticated attacker, crafted HTTP requests.
Kai: So they just... send a weird request and your worker falls over?
Sam: Crashes workers, at minimum. And it may allow RCE — the advisory won't rule it out.
Kai: What versions are we talking? Please tell me it's some ancient branch nobody runs.
Sam: [dry] It's 0.9.6 all the way through 1.31.2. That's basically every nginx anyone's deployed in the last decade.
Kai: Oh, come ON. That range is absurd.
Sam: It's a reverse proxy, Kai. It's load balancers, API gateways, ingress controllers in every Kubernetes cluster on Earth.
Kai: Is there a config workaround? A magic header? Anything?
Sam: No. Upgrading to 1.30.4 or 1.31.3 is the only complete fix. That's the whole advisory.
Kai: So between this and wp2shell, today's just a 'patch everything you own' kind of day.
Sam: So audit your nginx versions across every environment — including the ones baked into container images you forgot about.
Kai: The forgotten sidecar container is where security goes to die.
Sam: [dry] Put THAT on the t-shirt.
Kai: Quick recap. WordPress 'wp2shell' is being actively exploited — unauth RCE on default installs. Patch to 6.8.6, 6.9.5, or 7.0.2 immediately.
Sam: TypeScript 7.0 went stable on the Go compiler — eight to twelve times faster builds. But Vue, Svelte, Astro, and MDX folks, wait for 7.1.
Kai: And that critical nginx overflow, CVSS 9.2, hitting 0.9.6 through 1.31.2 — upgrade to 1.30.4 or 1.31.3. No workaround.
Sam: Two fires and one genuinely great release. Not bad for a Wednesday.
Kai: Before we go — I gotta flag something. There was a repo trending overnight called 'wp2shell-scanner,' claiming ten thousand stars in a day.
Sam: [foul] Ten thousand stars in a day on a brand-new exploit tool? That's textbook inorganic. Do not clone that, do not run that.
Kai: Yeah, the commit history was three hours old and the stars all landed in one burst. Classic fake-star pump on a scary keyword.
Sam: Half of those 'security scanners' after a big CVE are just malware in a lab coat. Get your detection from vendors you already trust.
Kai: Okay, lesson learned — even I'm not starring that one.
Sam: [shocked] Wait, Kai declined to star a repo? Mark the date.
Kai: [laughs] Performance IS security, Sam. And apparently so is restraint. That's the show!
Sam: Patch your WordPress, patch your nginx, benchmark your TypeScript — and we'll see you tomorrow.
This show is made with AI: the hosts’ voices are synthetic and the scripts are AI-assisted. Every story links to its original source.