hacker-news · Crawled Jul 17, 2026

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

1 IoCs
Read original article ↗

AI Summary

A critical unauthenticated remote code execution vulnerability, dubbed wp2shell, exists in WordPress core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. The flaw stems from a REST API batch-route confusion and SQL injection issue, allowing anonymous attackers to execute code on affected sites. WordPress released versions 6.9.5 and 7.0.2 on July 17, 2026, to address the vulnerability, and no exploitation has been reported as of July 18. Due to the lack of a CVE identifier, tracking must rely on version numbers and active monitoring of the batch endpoint.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Domain wp2shell[.]com Details →