In brief: An indexing flaw in the REST batch endpoint allows unauthenticated attackers to gain complete control over WordPress installations, but requires immediate patching to version 6.9.5 or 7.0.2.
WordPress installations from version 6.9.0 are affected by a critical vulnerability in the REST Batch API that enables unauthenticated remote code execution. The vulnerability has been fixed since WordPress 6.9.5 and 7.0.2.
The vulnerability, known as wp2shell (CVE-ID not disclosed), affects WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. The security flaw lies in the Core REST API component at the batch endpoint “batch/v1” and was first reported by Adam Kues of Searchlight Cyber.
An indexing error in request processing causes request objects and their permission checks to no longer be correctly mapped to each other. Attackers can thereby have a specially crafted batch request processed in the wrong authorization context and execute arbitrary code. Because the REST Batch API is enabled by default and is integrated into the WordPress core, affected installations are reachable via the endpoints “/wp-json/batch/v1” or “/?rest_route=/batch/v1” — even on systems without URL rewriting rules.
The security research team at Hadrian reconstructed the cause from the WordPress security patch of 17 July 2024. Anyone exploiting this vulnerability gains complete unauthenticated remote code execution on the web server, allowing the attacker to control the website and its content, access the database, and exfiltrate user credentials and personal data.
Hadrian recommends immediate updating to WordPress 6.9.5 or 7.0.2 and recommends as a workaround blocking access to both REST Batch API endpoints at the web server or WAF level. CISOs should also inventory all WordPress installations (including staging and abandoned campaign sites) and verify whether unrestricted REST API access is truly necessary.
Source: www.csoonline.com · Published 20 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.