wp2shell WordPress Flaw: Steps to Verify, Contain, and Check for Compromise

A critical WordPress vulnerability tracked as wp2shell affects versions 6.9.0–6.9.4 and 7.0.0–7.0.1, allowing attackers to execute code on exposed sites. WordPress enabled forced automatic updates to push patched versions 6.9.5 and 7.0.2, but these updates can silently fail in managed hosting environments, staging sites, or installs with auto-updates disabled. Sites that were unpatched after the July 17 disclosure are advised to actively check for signs of compromise, including unauthorized admin accounts and suspicious file modifications in wp-content. As a temporary measure for sites unable to patch immediately, blocking unauthenticated access to the /wp-json/batch/v1 REST endpoint via a WAF or plugin can reduce exposure, though this may disrupt some site functionality. Security experts stress that patching alone is insufficient if attackers have already gained access during the window of exposure.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in