Patch now: WordPress REST API bug allows remote code execution
Organizations running recent versions of WordPress are being asked to patch a newly detailed pre-authentication remote code execution (RCE) vulnerability affecting the platforms built-in REST Batch API. The flaw, dubbed wp2shell, enables attackers to execute arbitrary code against a default WordPress installation without requiring plugins, authentication, or special configuration. Adam Kues of Searchlight Cyber first reported the issue and published a public checker to assess risks, holding…
Read the full story at CSO Online ↗