CVE Tools
Back to feed
Research WordPress Core web-app WordPress rce

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

The Hacker News·By The Hacker News··4 min read
CVE Tools coverage

A newly discovered vulnerability in WordPress Core allows unauthenticated attackers to execute arbitrary code on affected installations. The flaw, named wp2shell, impacts versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. WordPress addressed the issue in versions 6.9.5 and 7.0.2, which were released on July 17, 2026. The vulnerability can be triggered via the REST API’s batch endpoint and requires no authentication or specific configuration. While no exploitation attempts have been observed yet, administrators are strongly advised to update immediately to mitigate risk.