Security researchers have uncovered a critical vulnerability in the WordPress core known as wp2shell, which allows unauthenticated attackers to remotely execute code on affected websites. Unlike many security flaws that rely on poorly configured third party plugins, this bug exists within the primary software itself, meaning even a completely bare installation is potentially exploitable. To combat the threat, WordPress has released emergency updates including versions 6.9.5 and 7.0.2, while utilizing its auto update system to force these patches onto as many sites as possible.
The exploit is actually a combination of two distinct vulnerabilities that work together like a key and a lock. One involves a SQL injection flaw where certain parameters fail to properly validate inputs, allowing an attacker to manipulate the database. The second part is a routing confusion within the REST API batch endpoint introduced in version 6.9. When chained together, these flaws bypass standard authentication checks entirely, granting an anonymous visitor the ability to run arbitrary commands on the server. While some sites using persistent object caches like Redis or Memcached might be inadvertently shielded from the remote code execution path, they remain vulnerable to the underlying SQL injection.
The urgency of the situation has escalated quickly following the publication of a working proof of concept on GitHub. Although there are currently no reports of widespread exploitation in the wild, experts warn that mass attacks on WordPress installations are common once a method becomes public knowledge. Because the flaw affects millions of potential installs across recent versions, administrators are urged not to rely solely on automatic updates and should manually verify their current version numbers immediately.
For those unable to update their systems right away, security teams suggest temporary mitigations such as blocking access to the specific batch endpoints via a web application firewall or disabling unauthenticated REST API access altogether. However, these are considered mere stopgaps that could interfere with legitimate site functionality. The long term solution remains updating to the latest secure version provided by WordPress developers to close the door on attackers before they can capitalize on the publicly available exploit maps.

