logo

Critical RCE Vulnerability in WordPress Core Exploited in the Wild

ID: 18475ceb-9981-54fa-a16b-a4758b16cdac

STIX ID: report--18475ceb-9981-54fa-a16b-a4758b16cdac

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-07-19

Date Updated: 2026-07-19

...
...

Searchlight Cyber has identified a critical pre-authentication RCE in WordPress Core impacting over 500 million sites; public proof-of-concept exploits are circulating and watchTowr reported early indications of exploitation in the wild. Site owners are urged to update to WordPress 7.0.2 or 6.9.5 immediately, and temporary mitigations (like blocking anonymous access to the batch API) may reduce risk but can affect legitimate use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.