Research WordPress Core web-app WordPress rce
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
CVE Tools coverage
A newly discovered vulnerability in WordPress Core allows unauthenticated attackers to execute arbitrary code on affected installations. The flaw, named wp2shell, impacts versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. WordPress addressed the issue in versions 6.9.5 and 7.0.2, which were released on July 17, 2026. The vulnerability can be triggered via the REST API’s batch endpoint and requires no authentication or specific configuration. While no exploitation attempts have been observed yet, administrators are strongly advised to update immediately to mitigate risk.