⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

July 17, 2026

A critical unauthenticated remote code execution vulnerability has been discovered in WordPress core, affecting versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. The flaw, dubbed ‘wp2shell’ by researcher Adam Kues of Assetnote (Searchlight Cyber’s attack surface management arm), can be exploited by an anonymous HTTP request against a default WordPress installation with no plugins. WordPress released emergency patches (6.9.5 and 7.0.2) on July 17, 2026, and enabled forced auto-updates to push the fix. The vulnerability is described as a REST API batch-route confusion and SQL injection issue leading to remote code execution. No CVE ID has been assigned yet, and no exploitation has been reported as of July 18. Mitigations include blocking the batch endpoint via WAF, disabling the REST API, or using a drop-in plugin to reject anonymous batch requests. Over 500 million websites run WordPress, though the vulnerable population is limited to installations from December 2025 onward.

Companies: WordPress, Assetnote, Searchlight Cyber

Products: WordPress