wp2shell: WordPress patches a Pre-Auth RCE that needed no plugins
Adam KuesSearchlight CyberRapid7WordPressHackerOne

wp2shell: WordPress patches a Pre-Auth RCE that needed no plugins

WordPress has patched a critical pre-authentication remote code execution vulnerability, dubbed wp2shell, affecting versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. The flaw, discovered by Adam Kues, allows attacks via a single web request without requiring plugins.

latesthackingnews.com26 July 2026 · 23:20 UTC
CuriousCats Full Story

WordPress has addressed a critical vulnerability known as wp2shell, which allows remote code execution without authentication on versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. The flaw was discovered by Adam Kues from Assetnote, who reported it through WordPress's HackerOne program.12

The vulnerability is described as “REST API batch-route confusion and SQL injection” that leads to remote code execution. It can be exploited via a single web request to the batch endpoint located at /wp-json/batch/v1 or its older alias ?rest_route=/batch/v1.

WordPress released patches in versions 6.9.5 and 7.0.2, with the GitHub Security Advisory rating the vulnerability as Critical with a CVSS score of 7.5. The project has implemented forced updates through its auto-update system to ensure all affected sites are patched, regardless of user action.

In light of the vulnerability's severity, Rapid7 Labs anticipates a public proof of concept (PoC) will emerge soon, and recommends blocking the batch endpoint at the WAF layer as a temporary measure. Site owners can verify their exposure using a public checker at wp2shell.com.345

As stated in the release notes, the vulnerability is classified as high severity by WordPress, but it is crucial not to underestimate its impact compared to other critical bugs.

Key Insight
“Rapid7 warns that a public exploit is likely soon because the patch diff is public and can be weaponized in hours. The firm also recommends defenders block the batch endpoint at the WAF layer as a temporary workaround.”
CuriousCats studied:
1
latesthackingnews.com
“A bare WordPress site with zero plugins was open to attack from a single, anonymous web request until yesterday.”
latesthackingnews.com →
Ask CuriousCats
What is wp2shell vulnerability?
Why is the WordPress patch significant?
How can this flaw be exploited?
Are there other WordPress vulnerabilities reported?
How does this compare to past exploits?
Become the most informed
person in the room.
Personal AI agents scanning 100,000+ sources — news, video, and social media — delivered every morning.
Download the App Go to CuriousCats.ai
🇺🇸 US🇮🇳 India🇬🇧 UK🇨🇦 Canada🇸🇬 Singapore
Liked the depth here?
Get the full internet briefed for you any time of the day.
Get CuriousCats