logo

Unauthenticated RCE in WordPress core (wp2shell), via SQL injection

ID: 2f7d82e3-ddec-5ab2-828c-e79e4e5637e6

STIX ID: report--2f7d82e3-ddec-5ab2-828c-e79e4e5637e6

Feed Name: Aikido Security's Blog

Threat Score
80/100

Date Published: 2026-07-17

Date Updated: 2026-07-24

...
...

WordPress released an emergency security update addressing an unauthenticated SQL injection in the REST batch endpoint (/wp-json/batch/v1) that can be chained to remote code execution; affected versions include 6.9.0–6.9.4 (fix: 6.9.5), 7.0.0–7.0.1 (fix: 7.0.2), and 7.1 beta (fix: beta2). The advisory urges immediate patching, outlines temporary mitigation options (WAF blocking of the path and rest_route parameter, blocking unauthenticated REST access), notes forced auto-updates for affected sites, and promotes runtime protection via Aikido Zen while tracking the issue in Aikido Intel.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.