Patch now: WordPress REST API bug allows remote code execution

Summary

A pre-authentication remote code execution (RCE) vulnerability, dubbed wp2shell, has been detailed in WordPress's REST Batch API. This flaw allows attackers to execute arbitrary code on affected WordPress installations without requiring plugins or authentication. Patches are available in versions 6.9.5 and 7.0.2 of WordPress Core.

IFF Assessment

FOE

This vulnerability allows unauthenticated remote code execution, giving attackers full control over a compromised WordPress site and its underlying server.

Severity

9.8 Critical (AI Estimated)

The vulnerability allows for pre-authentication remote code execution, meaning an attacker can compromise a system without needing valid credentials. The potential impact is very high, granting complete control over the web server and its data.

Defender Context

This critical RCE vulnerability in WordPress core requires immediate patching for all affected versions. Defenders should prioritize updating their WordPress instances and monitor for any signs of exploitation attempts targeting the REST Batch API.

Read Full Story →