logo

Critical RCE Vulnerability in WordPress Affects Over 500 Million Sites

ID: 9396b86f-fece-5b47-b727-3eb6f36c357e

STIX ID: report--9396b86f-fece-5b47-b727-3eb6f36c357e

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

...
...

On July 17, 2026 WordPress released version 7.0.2 (and 6.9.5 on the 6.9 branch) to patch a critical unauthenticated RCE vulnerability in the REST API batch endpoint that can be exploited on stock installations and affects over 500 million websites; forced auto-updates were enabled and administrators are advised to update immediately or temporarily block the REST API batch endpoint.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.