Are More Than 500 Million WordPress Websites at Risk? A New Critical “wp2shell” Vulnerability Allows Complete Remote Server Compromise!
A critical new vulnerability, dubbed “wp2shell,” has been discovered in WordPress, one of the world’s most widely used content management systems (CMS). If successfully exploited, this flaw allows attackers to execute arbitrary code remotely (Remote Code Execution – RCE) on the server and gain complete control over a website without authentication and without relying on any additional plugins.
According to security experts, this vulnerability could pose a serious threat to more than 500 million WordPress websites. As a result, the WordPress development team has released emergency security updates and is urging all users to update their systems immediately.
How does the “wp2shell” vulnerability work?
The vulnerability stems from a logical flaw in the REST API Batch Route mechanism within WordPress Core. This flaw creates a Batch Route Confusion issue during REST API request processing, enabling an attacker to perform an SQL Injection attack. The attack chain can then be escalated to achieve Remote Code Execution (RCE).
The most alarming aspect is that the attack does not require:
This means that virtually any vulnerable internet-facing WordPress installation could become a target for automated cyberattacks.
The vulnerability affects the following WordPress Core versions:
Additionally, the vulnerabilities have been assigned the following identifiers:
It is important to note that the WordPress 6.8 branch is only affected by the SQL Injection vulnerability and is not vulnerable to the RCE attack chain. This issue has been fixed in WordPress 6.8.6.
Remote Code Execution (RCE) vulnerabilities are considered among the most critical security flaws in cybersecurity.
An attacker who successfully exploits this vulnerability could:
This is an extract. The publication continues at the source.
Read the original at the source: https://uzcert.uz/en/are-more-than-500-million-wordpress-websites-at-risk-a-new-critical-wp2shell-vulnerability-allows-complete-remote-server-compromise-2/
Officially imported this from UZCERT’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- UZCERT — imported from official source
- Official source
- https://uzcert.uz/en/feed/ RSS
- Imported
- October 03, 2026 20:40
- Versions
- 1 recorded
- Identity
https://uzcert.uz/?p=39229