Critical RCE Vulnerability in WordPress Affects Over 500 Million Sites
ID: 9396b86f-fece-5b47-b727-3eb6f36c357e
STIX ID: report--9396b86f-fece-5b47-b727-3eb6f36c357e
Feed Name: ThreatCluster
Threat Score
On July 17, 2026 WordPress released version 7.0.2 (and 6.9.5 on the 6.9 branch) to patch a critical unauthenticated RCE vulnerability in the REST API batch endpoint that can be exploited on stock installations and affects over 500 million websites; forced auto-updates were enabled and administrators are advised to update immediately or temporarily block the REST API batch endpoint.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
