Patch now: WordPress REST API bug allows remote code execution

CSO ONLINEneutralcyber2026-07-20 12:32:36 UTC
AdYour ad here[email protected]

Organizations running recent versions of WordPress are being asked to patch a newly detailed pre-authentication remote code execution (RCE) vulnerability affecting the platforms built-in REST Batch API. The flaw, dubbed wp2shell, enables attackers to execute arbitrary code against a default WordPress installation without requiring plugins, authentication, or special configuration. Adam Kues of Searchlight Cyber first reported the issue and published a public checker to assess risks, holding…

Read the full story at CSO Online ↗
AdYour ad here[email protected]