WordPress Patches Pre-Authentication RCE Flaw Affecting Default Installations

A critical WordPress flaw lets anonymous attackers run code on unmodified sites; patches are now available.

Anonymous attackers can execute arbitrary code on default WordPress installations — no plugins, no account required — due to a newly disclosed vulnerability called wp2shell. Security researcher Adam Kues of Searchlight Cyber's Assetnote team discovered the flaw, which stems from a REST API batch-route confusion issue in WordPress Core. WordPress has issued emergency patches in versions 6.9.5 and 7.0.2 to address the vulnerability. The flaw is classified as a pre-authentication remote code execution (RCE) vulnerability, meaning attackers need no valid credentials to exploit it. Its presence in core WordPress — rather than a third-party plugin — means every standard installation running unpatched versions is potentially exposed. The patches cover both the current major branch (7.0.2) and the prior supported branch (6.9.5). WordPress powers a very large share of the web, with cybersecuritynews estimating more than 500 million sites run the platform globally, though that figure is not independently verified in the available reporting. Site administrators are urged to update immediately.

Why it matters

A core RCE vulnerability requiring no authentication is among the most severe classes of web security flaws, as any exposed site can be fully compromised without the attacker needing an account or specific configuration. Because the flaw exists in WordPress Core rather than an optional plugin, virtually every default installation on an affected version is at risk.

What's next

Site administrators running WordPress should update to version 6.9.5 or 7.0.2 immediately to close the vulnerability.

Key facts

Bias & framing notes

Both sources agree on the core facts — the vulnerability name, its pre-authentication RCE nature, the researcher, and the patched versions. Cybersecuritynews uses higher-alarm framing ('500 million+ websites at risk of full takeover') and labels it an emergency, while The Hacker News presents the same facts in more measured technical language. The 500 million figure appears only in cybersecuritynews and is not corroborated by the second source. No official WordPress security advisory was available among the sources to independently verify patch version numbers.

NewsClear — neutral news & congressional tracking · Bill of the Week