Table of Contents
Searchlight Cyber’s security research team has discovered a pre-authentication RCE in WordPress Core. The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins.
It is estimated that over 500 million websites use WordPress.
Given the severity of the bug and to give defenders time to patch, we are not releasing technical details at this time. We are, however, releasing a website to determine if your instance is vulnerable. You can find it here: wp2shell.com
wp2shell[.]com is a public tool developed by Searchlight Cyber
Affected WordPress versions
<= 6.8.5: not affected.6.9.0 - 6.9.4: affected.7.0.0 - 7.0.1: affected.
Mitigation
The best way to protect yourself is to update WordPress to version 7.0.2, or 6.9.5 if you are on the 6.9 branch. as soon as possible. If this isn’t possible, you can temporarily protect your instance by blocking anonymous access to the batch API, either by:
- Installing a plugin that blocks anonymous access to the rest API entirely; or
- Blocking
/wp-json/batch/v1and?rest_route=/batch/v1at a WAF level.
Note that both these solutions may have an impact on legitimate use of the site and should only be considered emergency temporary measures until you can update.
About Searchlight Cyber
Customers of Searchlight Cyber’s ASM solution, Assetnote, are always first to receive checks for the novel vulnerabilities we discover – often weeks or months before public disclosure. Our Security Research Team continues to dig beyond public PoCs to deliver high-signal detections to our platform. Learn more.
Explore related Content
Research
Out of Bounds, Out of Sandbox: RCE in Go JavaScript Engine
September 7, 2026
Research
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
July 20, 2026
Research
Smashing the ServiceNow Sandbox – Pre Authentication RCE
July 14, 2026
Research
CargoWise WebTracker – The Keys Were in the Cargo
June 25, 2026
Research
Two Bypasses for Chrome's Sanitizer API
May 22, 2026
Research
Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082)
May 21, 2026