New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released
ID: 3c1fe566-ef70-533c-8c67-15185d23bc8e
STIX ID: report--3c1fe566-ef70-533c-8c67-15185d23bc8e
Feed Name: cybersecurityNews.com
A critical pre-authentication remote code execution vulnerability dubbed **wp2shell** has been disclosed in WordPress Core allowing anonymous attackers to achieve full takeover of affected installations via a REST API batch-route confusion that leads to SQL injection and RCE. The flaw impacts specific WordPress releases (6.9.0–6.9.4, 7.0.0–7.0.1, and a 7.1 beta), WordPress.org released fixes (7.0.2, 6.9.5, 6.8.6) and force-pushed auto-updates, and administrators are urged to apply patches immediately or temporarily block the affected REST endpoints or restrict anonymous REST access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
