Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Patch now! Researchers disclose WordPress core remote code execution bug, exploitation underway

Millions of websites worldwide, including in Australia, are likely vulnerable to a newly revealed pre-authentication RCE.

Mon, 20 Jul 2026
Patch now! Researchers disclose WordPress core remote code execution bug, exploitation underway

“WordPress gets a bad rap for security,” Benjamin Harris said.

Harris, cyber security firm watchTowr’s CEO, isn’t wrong, but the latest vulnerability in the highly popular web content management system is, according to him, “highly rare”.

“The reality is that a highly impactful, unauthenticated SQL injection or remote code execution vulnerability in WordPress core is actually fairly rare,” Harris told Cyber Daily, referring to the vulnerability already known as wp2shell, which was recently disclosed by Searchlight Cyber.

 
 

Details of the vulnerability – a pre-authentication RCE in WordPress core – are light on the ground at the moment, purely because of its impact.

“The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins,” Searchlight Cyber said in a 17 July advisory.

“It is estimated that over 500 million websites use WordPress.

“Given the severity of the bug and to give defenders time to patch, we are not releasing technical details at this time.”

That said, the company has published a website where WordPress users can check if their instance is vulnerable: https://wp2shell.com/

Broadly speaking, however, the vulnerability impacts versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. 6.8.5 and below is unaffected. According to Searchlight Cyber, the best mitigation advice is to update any WordPress instances to either version 7.0.2 or 6.9.5, depending on which branch of the platform users are on.

Otherwise, WordPress users are advised to install a plugin that blocks anonymous access to the REST API entirely, or block /wp-json/batch/v1 and ?rest_route=/batch/v1 at a WAF level.

Harris said that despite how new this vulnerability is, watchTowr is already seeing proof-of-concept exploits in circulation, with initial signs that exploitation is underway.

“This is going to hurt. WordPress runs on hundreds of millions of websites globally. Some of those will be auto-patched by their hosting providers, but plenty will not, and that is where the damage will be done,” Harris said.

“Our advice is simple: patch as fast as you possibly can, and do not stop there. Put the controls and investigations in place to determine whether an attacker got there first and to detect and remove any backdoors that may already have been dropped before you patched.”

Harris also noted that the speed of disclosure and the time-to-weaponise is a clear indicator of the impact of artificial intelligence.

“We saw PoCs appear within hours of disclosure, where historically that would have taken 24 hours or more,” Harris said.

“The window between disclosure and exploitation has collapsed, and WordPress is simply today’s reminder of it.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags:

David Hollingworth

David Hollingworth has been writing about technology for over 20 years, and has worked for a range of print and online titles in his career. He is enjoying getting to grips with cyber security, especially when it lets him talk about Lego.