Bottom line: The wp2shell core vulnerability in WordPress 6.9 and 7.0 enables code execution through anonymous HTTP requests and has been patched by security updates 6.9.5 and 7.0.2 with forced auto-updates.
A security vulnerability in the WordPress core allows unauthenticated attackers to execute arbitrary code on affected websites. The vulnerability also affects plain WordPress installations without additional plugins.
The wp2shell vulnerability exists in WordPress standard installations without additional extensions and thus lies in the core codebase. Through simple, unauthenticated HTTP requests, attackers can execute arbitrary code on affected servers.
All WordPress installations of versions 6.9 and 7.0 were affected — until WordPress released patch versions 6.9.5 and 7.0.2 on Friday and enabled forced auto-updates through its automatic update system.
Adam Kues from the security company Assetnote (Attack-Surface-Management division of Searchlight Cyber) discovered the vulnerability and responsibly disclosed it to WordPress.
Source: thehackernews.com · Published July 17, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.