WordPress has released critical security updates for versions 6.9.x and 7.0.x to patch a dangerous remote code execution vulnerability chain that allows attackers to compromise sites without authentication.
Key Points
- WordPress versions 6.9.0–6.9.4 and 7.0.0–7.0.1 are vulnerable to a pre-authentication remote code execution exploit known as wp2shell.
- The flaw chains a REST API batch-route confusion bug (CVE-2026-63030) with a high-severity SQL injection (CVE-2026-60137).
- WordPress has issued mandatory forced automatic updates to version 7.0.2 and 6.9.5 to mitigate the risk for affected installations.
- Researchers at Searchlight Cyber discovered the vulnerabilities, which can be exploited by anonymous users on default WordPress configurations without requiring plugins.
- Administrators can use a provided online tool to check if their specific WordPress instance is currently vulnerable to these exploits.