{"id":8817,"date":"2026-07-20T12:30:13","date_gmt":"2026-07-20T12:30:13","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=8817"},"modified":"2026-07-20T12:30:13","modified_gmt":"2026-07-20T12:30:13","slug":"patch-now-wordpress-rest-api-bug-allows-remote-code-execution","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=8817","title":{"rendered":"Patch now: WordPress REST API bug allows remote code execution"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Organizations running recent versions of WordPress are being asked to patch a newly detailed pre-authentication remote code execution (RCE) vulnerability affecting the platform\u2019s built-in REST Batch API.<\/p>\n<p class=\"wp-block-paragraph\">The flaw, dubbed wp2shell, enables attackers to execute arbitrary code against a default WordPress installation without requiring plugins, authentication, or special configuration.<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/adam-kues\/\" target=\"_blank\" rel=\"noopener\">Adam Kues<\/a> of Searchlight Cyber first reported the issue and published a public <a href=\"https:\/\/wp2shell.com\/\" target=\"_blank\" rel=\"noopener\">checker<\/a> to assess risks, holding back technical details until a patch was available and admins had enough time to apply it.<\/p>\n<p class=\"wp-block-paragraph\">In a technical analysis published by Hadrian, researchers reconstructed the root cause from WordPress\u2019 <a href=\"https:\/\/wordpress.org\/news\/2026\/07\/wordpress-7-0-2-release\/\" target=\"_blank\" rel=\"noopener\">security patch<\/a> released on July 17. The vulnerability, they said, resides in the core REST API batch endpoint \u201cbatch\/v1,\u201d where an indexing mismatch during request validation can cause request objects and their associated permission checks to become misaligned.<\/p>\n<p class=\"wp-block-paragraph\">As a result, a crafted batch request can be processed under the wrong authorization context, ultimately allowing remote code execution.<\/p>\n<p class=\"wp-block-paragraph\">\u201cAn attacker who reaches the bug gains unauthenticated code execution on the web server,\u201d the researchers <a href=\"https:\/\/hadrian.io\/blog\/wp2shell-a-pre-authentication-rce-in-wordpress-cores-rest-batch-api\" target=\"_blank\" rel=\"noopener\">said.<\/a> \u201cIn practice, that means full control of the site and its content, access to the database and whatever credentials or personal data it holds, and a way into the surrounding hosting environment.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The issue affects WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. According to Hadrian, versions 6.9.5 and 7.0.2 contain the fix, while 6.8.6 includes the same hardening changes even though earlier 6.8.x releases are not affected by this specific vulnerability.<\/p>\n<p class=\"wp-block-paragraph\">Because the vulnerable component is part of WordPress Core and the REST Batch API is enabled by default, any affected site exposing the REST API is potentially reachable by attackers. The researchers said this endpoint remains accessible through both \u201c\/wp-json\/batch\/v1\u201d and the alternate \/\u201c?rest_route=\/batch\/v1\u201d path, even on deployments without rewrite rules.<\/p>\n<p class=\"wp-block-paragraph\">Hadrian recommended upgrading immediately to WordPress 6.9.5 or 7.02, verifying that updates completed successfully, and, where patching cannot be performed immediately, blocking unauthorized access to both REST Batch API endpoints at the web server and through <a href=\"https:\/\/www.csoonline.com\/article\/563657\/calling-barracudas-waf-a-firewall-is-seriously-selling-it-short.html\">WAF<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">Organizations were also advised to inventory all WordPress deployments, including staging and forgotten campaign sites, and review whether unauthorized access to the REST API is necessary for their environment.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Organizations running recent versions of WordPress are being asked to patch a newly detailed pre-authentication remote code execution (RCE) vulnerability affecting the platform\u2019s built-in REST Batch API. The flaw, dubbed wp2shell, enables attackers to execute arbitrary code against a default WordPress installation without requiring plugins, authentication, or special configuration. Adam Kues of Searchlight Cyber first [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":8818,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-8817","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8817"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=8817"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/8817\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/8818"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=8817"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=8817"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=8817"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}