BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

WordPress core hit by zero-click RCE bug, patch now live

WordPress patches pre-auth RCE flaw discovered by Adam Kues in versions 6.9.5 and 7.0.2.

  • WordPress patched a pre-authentication remote code execution flaw in versions 6.9.5 and 7.0.2 on July 17, 2026.
  • The bug, found by Adam Kues of Searchlight Cyber’s Assetnote, allows an anonymous HTTP request to run code on a default install with zero plugins.
  • No CVE ID or CVSS score has been assigned yet, and no exploitation attempts have been reported as of July 18.
  • Mitigations include blocking the /wp-json/batch/v1 endpoint at a WAF or disabling the REST API entirely.

An anonymous HTTP request can remotely execute code on any WordPress site running versions 6.9.0 through 6.9.4 or 7.0.0 through 7.0.1, even on a bare install with no plugins. Adam Kues at Assetnote, the attack surface management arm of Searchlight Cyber, discovered the flaw and reported it through WordPress’s HackerOne program. The firm’s writeup, published under the name wp2shell, states the attack has “no preconditions and can be exploited by an anonymous user.”

- Advertisement -

WordPress shipped 6.9.5 and 7.0.2 on July 17, 2026, and enabled forced updates through its auto-update system. However, the company has not said whether the forced push reaches sites that turned auto-updates off. The release post describes the finding as “a REST API batch-route confusion and SQL injection issue leading to Remote Code Execution.” The batch endpoint has existed since WordPress 5.6 in November 2020, and nothing published so far explains what changed in version 6.9 to open it.

Neither advisory carries a CVE ID or a CVSS score, and no CVE record had appeared by July 18. Consequently, CISA cannot add the flaw to its KEV catalog until a CVE is assigned. Searchlight’s post estimates that over 500 million websites run WordPress, though only those on releases from 6.9 onward (shipped December 2, 2025) are affected. For administrators unable to update immediately, Searchlight Cyber recommends blocking both /wp-json/batch/v1 and rest_route=/batch/v1 at a WAF, or disabling the REST API altogether. No exploitation attempts have been reported as of July 18, but with no public signature to match, visibility remains limited.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Trump could net big tax windfall from crypto ethics plan

A bipartisan ethics proposal tied to a crypto market structure bill includes a tax-deferral...

Musk’s Terafab: 50x Pentagon, $16.8B, 3,000 jobs

Elon Musk outlined Terafab’s massive scale, saying the Texas semiconductor complex will be 50...

MARA swings to $611M loss despite record Bitcoin production

MARA swung to a net loss of $611.3 million in Q2 2026, driven by...

SEC Bought Airline Ticket Data Without Warrant, Docs Show

The SEC purchased access to a global airline ticketing database with over 1 billion...

Theta launches new AI gaming vertical, ships AI Characters

Ant Digital Technologies' Web3 brand, ZAN, joined the Theta ecosystem as a strategic Enterprise...

Must Read

How to Choose a Cryptocurrency Exchange: Major Risks and Expert Advice

During the bitcoin frenzy, in late 2017, Coinbase, one of the key players in the global cryptocurrency market, stopped trading operations. At a point...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading