logo

New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released

ID: 3c1fe566-ef70-533c-8c67-15185d23bc8e

STIX ID: report--3c1fe566-ef70-533c-8c67-15185d23bc8e

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

Author: Guru Baran

...
...

A critical pre-authentication remote code execution vulnerability dubbed **wp2shell** has been disclosed in WordPress Core allowing anonymous attackers to achieve full takeover of affected installations via a REST API batch-route confusion that leads to SQL injection and RCE. The flaw impacts specific WordPress releases (6.9.0–6.9.4, 7.0.0–7.0.1, and a 7.1 beta), WordPress.org released fixes (7.0.2, 6.9.5, 6.8.6) and force-pushed auto-updates, and administrators are urged to apply patches immediately or temporarily block the affected REST endpoints or restrict anonymous REST access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.