logo

Imperva Customers Protected Against “wp2shell” Pre-Authentication RCE in WordPress Core

ID: f3ed07bc-eb37-5693-aea9-4e5a43d166a5

STIX ID: report--f3ed07bc-eb37-5693-aea9-4e5a43d166a5

Feed Name: Security Boulevard

Threat Score
80/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

Author: Bar Menachem

...
...

A critical pre-authentication Remote Code Execution vulnerability dubbed "wp2shell" (CVE-2026-63030) has been identified in the WordPress REST API endpoints /wp-json/batch/v1 and ?rest_route=/batch/v1 affecting WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1; administrators are urged to update to 6.9.5 or 7.0.2 immediately, apply WAF/WAF-GW policy updates, or temporarily block the vulnerable endpoints to mitigate risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.