BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

WordPress core hit by zero-click RCE bug, patch now live

WordPress patches pre-auth RCE flaw discovered by Adam Kues in versions 6.9.5 and 7.0.2.

  • WordPress patched a pre-authentication remote code execution flaw in versions 6.9.5 and 7.0.2 on July 17, 2026.
  • The bug, found by Adam Kues of Searchlight Cyber’s Assetnote, allows an anonymous HTTP request to run code on a default install with zero plugins.
  • No CVE ID or CVSS score has been assigned yet, and no exploitation attempts have been reported as of July 18.
  • Mitigations include blocking the /wp-json/batch/v1 endpoint at a WAF or disabling the REST API entirely.

An anonymous HTTP request can remotely execute code on any WordPress site running versions 6.9.0 through 6.9.4 or 7.0.0 through 7.0.1, even on a bare install with no plugins. Adam Kues at Assetnote, the attack surface management arm of Searchlight Cyber, discovered the flaw and reported it through WordPress’s HackerOne program. The firm’s writeup, published under the name wp2shell, states the attack has “no preconditions and can be exploited by an anonymous user.”

- Advertisement -

WordPress shipped 6.9.5 and 7.0.2 on July 17, 2026, and enabled forced updates through its auto-update system. However, the company has not said whether the forced push reaches sites that turned auto-updates off. The release post describes the finding as “a REST API batch-route confusion and SQL injection issue leading to Remote Code Execution.” The batch endpoint has existed since WordPress 5.6 in November 2020, and nothing published so far explains what changed in version 6.9 to open it.

Neither advisory carries a CVE ID or a CVSS score, and no CVE record had appeared by July 18. Consequently, CISA cannot add the flaw to its KEV catalog until a CVE is assigned. Searchlight’s post estimates that over 500 million websites run WordPress, though only those on releases from 6.9 onward (shipped December 2, 2025) are affected. For administrators unable to update immediately, Searchlight Cyber recommends blocking both /wp-json/batch/v1 and rest_route=/batch/v1 at a WAF, or disabling the REST API altogether. No exploitation attempts have been reported as of July 18, but with no public signature to match, visibility remains limited.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Micron 628% rally sparks MU stock forecast 2036 debate

Micron's stock has soared roughly 628% over the past year, presenting a forward P/E...

Circle Launches Arc Mainnet With BlackRock, Visa as Validators

Circle’s Arc mainnet went live Wednesday with over 100 institutional partners, including BlackRock, Mastercard,...

Zcash Rallies 7% as Only Top Crypto Gainer; Ledger Integration Planned

ZCash (ZEC) rose over 7% in 24 hours, making it the only top-ten cryptocurrency...

Trump & Melania memecoins crash 97%, 99%

Trump memecoin ($TRUMP) has plunged 97% from its all-time high of ~$75 to ~$2...

Zcash holders vote to cut block time to 25 seconds, keep halvings

ZCash token holders voted 99.9% in favor of cutting the network's target block time...

Must Read

How To Travel With Bitcoin: 9 Travel Companies Accepting Bitcoin

Bitcoin travel is a reality, as several travel companies now accept payments in cryptocurrencies for their services.Those who have opened a Bitcoin account on...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading