BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

WordPress core hit by zero-click RCE bug, patch now live

WordPress patches pre-auth RCE flaw discovered by Adam Kues in versions 6.9.5 and 7.0.2.

  • WordPress patched a pre-authentication remote code execution flaw in versions 6.9.5 and 7.0.2 on July 17, 2026.
  • The bug, found by Adam Kues of Searchlight Cyber’s Assetnote, allows an anonymous HTTP request to run code on a default install with zero plugins.
  • No CVE ID or CVSS score has been assigned yet, and no exploitation attempts have been reported as of July 18.
  • Mitigations include blocking the /wp-json/batch/v1 endpoint at a WAF or disabling the REST API entirely.

An anonymous HTTP request can remotely execute code on any WordPress site running versions 6.9.0 through 6.9.4 or 7.0.0 through 7.0.1, even on a bare install with no plugins. Adam Kues at Assetnote, the attack surface management arm of Searchlight Cyber, discovered the flaw and reported it through WordPress’s HackerOne program. The firm’s writeup, published under the name wp2shell, states the attack has “no preconditions and can be exploited by an anonymous user.”

- Advertisement -

WordPress shipped 6.9.5 and 7.0.2 on July 17, 2026, and enabled forced updates through its auto-update system. However, the company has not said whether the forced push reaches sites that turned auto-updates off. The release post describes the finding as “a REST API batch-route confusion and SQL injection issue leading to Remote Code Execution.” The batch endpoint has existed since WordPress 5.6 in November 2020, and nothing published so far explains what changed in version 6.9 to open it.

Neither advisory carries a CVE ID or a CVSS score, and no CVE record had appeared by July 18. Consequently, CISA cannot add the flaw to its KEV catalog until a CVE is assigned. Searchlight’s post estimates that over 500 million websites run WordPress, though only those on releases from 6.9 onward (shipped December 2, 2025) are affected. For administrators unable to update immediately, Searchlight Cyber recommends blocking both /wp-json/batch/v1 and rest_route=/batch/v1 at a WAF, or disabling the REST API altogether. No exploitation attempts have been reported as of July 18, but with no public signature to match, visibility remains limited.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Justin Sun admits Poloniex is his personal exchange

Justin Sun admitted that his exchange Poloniex is used solely by himself, implying wash...

UK names six banks to lead first digital gilt bond pilot

The UK government has appointed six major banks, including Barclays, HSBC, and Morgan Stanley,...

Mistral Launches ‘Le Chonk’ AI Model With 1 Trillion Parameters

Mistral AI launched Large 4 on Oct. 6, a 1-trillion-parameter model that activates 49...

Ripple expands Brevan Howard deal with prime brokerage

Ripple Prime will provide multi-asset prime brokerage, clearing, and financing services to funds managed...

Micron Stock Rally: HBM Shortage, Record Earnings, Targets

Micron shares surged 272.78% year-to-date, closing at $1,063.96 on October 5.Record fiscal 2026 revenue...

Must Read

The Ultimate Guide on How to Understand a Cryptocurrency White Paper

Today, cryptocurrency is a popular buzzword. We hear about it on the news, we read about it on the Internet. Yet, people are reluctant to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading