CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2783

As cited

Copy frozen at (site build).

vulnerabilities

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

A critical vulnerability in WordPress core versions 6.9 and 7.0 allowed unauthenticated attackers to execute arbitrary code on unpatched installations. WordPress released patches (6.9.5 and 7.0.2) on Friday and deployed forced updates through its auto-update mechanism. Adam Kues at Assetnote discovered the flaw and coordinated its disclosure.

Why it matters: WordPress site operators must verify they are running 6.9.5, 7.0.2, or newer immediately, as this unauthenticated remote code execution affects core installations with no plugins and requires only a bare HTTP request to exploit.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

A critical vulnerability in WordPress core versions 6.9 and 7.0 allowed unauthenticated attackers to execute arbitrary code on unpatched installations. WordPress released patches (6.9.5 and 7.0.2) on Friday and deployed forced updates through its auto-update mechanism. Adam Kues at Assetnote discovered the flaw and coordinated its disclosure.

Why it matters: WordPress site operators must verify they are running 6.9.5, 7.0.2, or newer immediately, as this unauthenticated remote code execution affects core installations with no plugins and requires only a bare HTTP request to exploit.

VendorsCloudflareGitHubWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary