Patch now: WordPress REST API bug allows remote code execution
Summary
A pre-authentication remote code execution (RCE) vulnerability, dubbed wp2shell, has been detailed in WordPress's REST Batch API. This flaw allows attackers to execute arbitrary code on affected WordPress installations without requiring plugins or authentication. Patches are available in versions 6.9.5 and 7.0.2 of WordPress Core.
IFF Assessment
This vulnerability allows unauthenticated remote code execution, giving attackers full control over a compromised WordPress site and its underlying server.
Severity
The vulnerability allows for pre-authentication remote code execution, meaning an attacker can compromise a system without needing valid credentials. The potential impact is very high, granting complete control over the web server and its data.
Defender Context
This critical RCE vulnerability in WordPress core requires immediate patching for all affected versions. Defenders should prioritize updating their WordPress instances and monitor for any signs of exploitation attempts targeting the REST Batch API.