WordPress Core “Wp2shell” RCE Flaws Get Public Exploits, Patch Now

Critical remote code execution vulnerabilities named “wp2shell” affecting WordPress Core versions 6.9.x and 7.0.x have public exploits released, enabling unauthenticated attackers to fully compromise default installations. The flaws stem from a REST API batch-route confusion bug and an SQL injection in WP_Query, which can be chained for pre-authentication RCE; WordPress has issued emergency updates (6.9.5 and 7.0.2) with forced auto-updates enabled, and administrators are urged to patch immediately or apply temporary mitigations such as blocking REST API access. Cloudflare has also deployed WAF rules to reduce exposure, but these do not replace the need for timely updates as in-the-wild exploitation has already been observed.

https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top