Searchlight Cyber’s security research team has discovered a pre-authentication RCE in WordPress Core. The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins.
It is estimated that over 500 million websites use WordPress.
Given the severity of the bug and to give defenders time to patch, we are not releasing technical details at this time. We are, however, releasing a website to determine if your instance is vulnerable. You can find it here:
Check if your site is impacted wp2shell[.]com is a public tool developed by Searchlight Cyber
The best way to protect yourself is to update WordPress to version 7.0.2, or 6.9.5 if you are on the 6.9 branch. as soon as possible. If this isn’t possible, you can temporarily protect your instance by blocking anonymous access to the batch API, either by:
Note that both these solutions may have an impact on legitimate use of the site and should only be considered emergency temporary measures until you can update.
Searchlight Cyber is used by security professionals and leading investigators to surface criminal activity and protect businesses. Book your demo to find out how Searchlight can:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
