
Patch now: WordPress REST API bug allows remote code execution
Organizations running recent versions of WordPress are being asked to patch a newly detailed pre-authentication remote code execution (RCE) vulnerability affecting the platform’s built-in REST Batch API.
The flaw, dubbed wp2shell, enables attackers to execute arbitrary code against a default WordPress installation without requiring plugins, authentication, or special configuration.
Adam Kues of Searchlight Cyber first reported the issue and published a public checker to assess risks, holding back technical details until a patch was available and admins had enough time to apply it.
In a technical analysis published by Hadrian, researchers reconstructed the root cause from WordPress’ security ...