News·3 min read

Critical WordPress wp2shell Flaw Lets Anonymous Attackers Execute Remote Code

A critical pre-authentication remote code execution (RCE) vulnerability in WordPress Core, dubbed “wp2shell.” The flaw requires no preconditions and can be exploited by an anonymous attack

CS
CyberShield Team
2026-07-18
Share:
Critical WordPress wp2shell Flaw Lets Anonymous Attackers Execute Remote Code

A critical pre-authentication remote code execution (RCE) vulnerability in WordPress Core, dubbed “wp2shell.” The flaw requires no preconditions and can be exploited by an anonymous attacker against a stock WordPress installation with zero plugins active, putting a significant chunk of the estimated 500 million WordPress-powered websites at immediate risk. Critical WordPress wp2shell Flaw The bug, […] The post Critical WordPress wp2shell Flaw Lets Anonymous Attackers Execute Remote Code appeared first on Cyber Security News.

A critical pre-authentication remote code execution (RCE) vulnerability in WordPress Core, dubbed “wp2shell.” The flaw requires no preconditions and can be exploited by an anonymous attacker against a stock WordPress installation with zero plugins active, putting a significant chunk of the estimated 500 million WordPress-powered websites at immediate risk. Critical WordPress wp2shell Flaw The bug, discovered by Adam Kues of Assetnote, stems from a REST API batch-route confusion that enables SQL injection and ultimately culminates in full remote code execution. Given the severity and pre-auth nature of the exploit, Searchlight Cyber has withheld technical specifics to give site owners time to patch before proof-of-concept details potentially surface. To help administrators assess exposure, the research team released a public scanning tool at wp2shell[.]com, allowing site owners to check whether their installation is vulnerable. Affected Versions WordPress ≤6.8.5: not affected WordPress 6.9.0–6.9.4: affected WordPress 7.0.0–7.0.1: affected WordPress 7.1 beta (pre-release): affected Two CVE identifiers have been assigned to track the issue. CVE-2026-60137 (GHSA-fpp7-x2x2-2mjf) covers a facilitated SQL injection issue in the WP_Query component. CVE-2026-63030 (GHSA-ff9f-jf42-662q), with a CVSS score of 7.5 despite its critical classification, covers the REST API batch-route confusion chain that leads to RCE. Patch Availability WordPress has responded swiftly with the 7.0.2 security release, which patches both the critical and a high-severity issue. Backport fixes are also available: WordPress 6.9.5 — patches both vulnerabilities WordPress 6.8.6 — patches the SQL injection issue only (6.8.x was not affected by the RCE chain) WordPress 7.1 beta2 — patches both issues ahead of the 7.1 stable release Due to the critical severity, the WordPress team has enabled forced automatic updates for sites still running affected versions, even those that normally have auto-updates disabled for major releases. Mitigation Site owners are urged to update immediately, either via the WordPress Dashboard (“Updates” > “Update Now”) or by manually downloading version 7.0.2 from WordPress.org. For environments that cannot patch immediately, Searchlight Cyber recommends emergency temporary measures: Install a plugin that blocks anonymous access to the REST API entirely; block/wp-json/batch/v1 and ?rest_route=/batch/v1 at the WAF level Both workarounds may disrupt legitimate REST API usage and should be treated strictly as stopgap measures until the official patch is applied. Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs The post Critical WordPress wp2shell Flaw Lets Anonymous Attackers Execute Remote Code appeared first on Cyber Security News.

Share:

Join the Discussion

Comments coming soon. Follow us on social media for real-time discussions.