Skip to content
Wp2shell Pre Authentication Rce In Word Press Core

Wp2shell Pre Authentication Rce In Word Press Core

slcyber.io July 21, 2026

Searchlight Cyber’s security research team has discovered a pre-authentication RCE in WordPress Core. The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins.

It is estimated that over 500 million websites use WordPress.

Given the severity of the bug and to give defenders time to patch, we are not releasing technical details at this time. We are, however, releasing a website to determine if your instance is vulnerable. You can find it here:

Check if your site is impacted wp2shell[.]com is a public tool developed by Searchlight Cyber

The best way to protect yourself is to update WordPress to version 7.0.2, or 6.9.5 if you are on the 6.9 branch. as soon as possible. If this isn’t possible, you can temporarily protect your instance by blocking anonymous access to the batch API, either by:

Note that both these solutions may have an impact on legitimate use of the site and should only be considered emergency temporary measures until you can update.

Searchlight Cyber is used by security professionals and leading investigators to surface criminal activity and protect businesses. Book your demo to find out how Searchlight can:

Extracted Entities

Attack Types (1)

CWE Weaknesses (1)

Domains (1)

Platforms (1)

Vulnerabilities (1)