Unauthenticated RCE in WordPress core (wp2shell), via SQL injection
ID: 2f7d82e3-ddec-5ab2-828c-e79e4e5637e6
STIX ID: report--2f7d82e3-ddec-5ab2-828c-e79e4e5637e6
Feed Name: Aikido Security's Blog
WordPress released an emergency security update addressing an unauthenticated SQL injection in the REST batch endpoint (/wp-json/batch/v1) that can be chained to remote code execution; affected versions include 6.9.0–6.9.4 (fix: 6.9.5), 7.0.0–7.0.1 (fix: 7.0.2), and 7.1 beta (fix: beta2). The advisory urges immediate patching, outlines temporary mitigation options (WAF blocking of the path and rest_route parameter, blocking unauthenticated REST access), notes forced auto-updates for affected sites, and promotes runtime protection via Aikido Zen while tracking the issue in Aikido Intel.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
