Searchlight Cyber has disclosed a critical pre-authentication Remote Code Execution (RCE) vulnerability in WordPress Core, affecting versions prior to 6.9.5 and 7.0.2. Due to the severity and the fact that it requires no authentication or plugins, immediate updating is strongly recommended for all WordPress installations.
Background
WordPress powers over 500 million websites, making any core-level vulnerability potentially catastrophic. This specific flaw allows anonymous attackers to execute arbitrary code without any prerequisites.
- Source
- Lobsters
- Published
- Jul 19, 2026 at 02:12 AM
- Score
- 9.0 / 10