A validation flaw in WordPress’s REST Batch API enables pre-authentication remote code execution with full control over website, database, and hosting environment.
An indexing flaw in the REST batch endpoint allows unauthenticated attackers to gain complete control over WordPress installations, but requires immediate patching to version 6.9.5 or 7.0.2.
The wp2shell core vulnerability in WordPress 6.9 and 7.0 enables code execution through anonymous HTTP requests and has been patched by security updates 6.9.5 and 7.0.2 with forced auto-updates.