Critical RCE Vulnerability in WordPress Core Exploited in the Wild

Critical RCE Vulnerability in WordPress Core Exploited in the Wild

First seen 19 Jul 2026, 11:17 UTC Techechelonslcyber.io 71% similarity 72.9

Article Content

Browse articles
ThreatCluster

Searchlight Cyber has identified a pre-authentication remote code execution (RCE) vulnerability in WordPress Core, affecting over 500 million websites. The flaw can be exploited by anonymous users on stock installations without plugins. Public proof-of-concept exploits are circulating, prompting security firm watchTowr to report early signs of exploitation in the wild. Site owners are urged to update to WordPress versions 7.0.2 or 6.9.5 immediately to mitigate risks. Temporary measures include blocking anonymous access to the batch API, though these may impact legitimate site use. The vulnerability is critical due to its potential for widespread exploitation. Technical details are withheld to give defenders time to patch their systems. The situation is evolving, and ongoing monitoring is advised.

Key Points: • A critical RCE vulnerability in WordPress Core affects over 500 million sites. • Public exploits are circulating, leading to active exploitation in the wild. • Immediate updates to WordPress versions 7.0.2 or 6.9.5 are strongly recommended.

ThreatCluster AI

Timeline

2026-07-19
RCE vulnerability discovered
Searchlight Cyber identified a pre-authentication RCE vulnerability in WordPress Core, affecting stock installations.
slcyber.io
2026-07-19
Public exploits circulate
Security firm watchTowr reported early signs of exploitation of the wp2shell vulnerabilities in the wild.
Techechelon
2026-07-19
Urgent update recommendation issued
Site owners are urged to update to WordPress versions 7.0.2 or 6.9.5 immediately to mitigate the vulnerability.
Techechelon

Community

Browse all →