logo

GPT-5.6 Sol Ultra Discovers WordPress Pre-Auth SQL Injection Leading to RCE

ID: 7a33ba32-3f54-5648-933e-d9939b58ce54

STIX ID: report--7a33ba32-3f54-5648-933e-d9939b58ce54

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Divya

...
...

This report describes a critical multi-stage vulnerability chain called "wp2shell" in WordPress's REST Batch API that enables unauthenticated attackers to trigger a pre-auth SQL injection in the posts-listing endpoint, forge WP_Post objects in cache, escalate privileges by creating a temporary administrator account, and ultimately install a malicious plugin to achieve remote code execution; administrators are advised to apply updates, restrict public REST access, review logs for /wp-json/batch/v1 activity, and investigate unexpected admin accounts or plugin installs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.