Just in:
The Mineral Boutique Limited Welcomes CCS Clarification and Reaffirms Asia Growth Strategy // Drone strike damages Kuwait residential complex, no injuries // Ingdan, Inc. (400.HK) Announces 2026 Interim Results // Jordan downs eight missiles as Iran targets US bases // Dubai hotel provides free public co-working space // Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” // Qatar economy contracts 7% as energy output slumps // India plans own orbital space outpost, second after China // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // Apple raises evidence-destruction claims against OpenAI // Russia brings cryptocurrency market law into force // WisPaper Introduces TrueCite to Help Researchers Verify AI-Generated Academic References // Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // Adobe widens Saudi AI access with $4 billion programme // Macao Economic, Trade, and Tourism Investment Promotion Seminar Convened in Jakarta, Indonesia, Fostering Multi-Dimensional Cooperation to Jointly Explore New Opportunities Along the Silk Road // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // LatAm gushers and possible Venezuela exit a nightmare for Opec // What Shein’s $27bn IPO means for Mubadala // Haldwani purification row: Caste back on political centre-stage // Alpha Dhabi lifts MICAD commitment to $1 billion //

WordPress patches critical flaw enabling site takeover

WordPress has issued emergency security updates to block a critical vulnerability that allowed unauthenticated attackers to execute code on websites running standard installations without plugins.

The flaw, dubbed “wp2shell” and tracked as CVE-2026-63030, affected WordPress 6.9.0 through 6.9.4 and versions 7.0.0 and 7.0.1. WordPress released versions 6.9.5 and 7.0.2 on July 17, urging administrators to install the patches immediately.

The vulnerability carried exceptional risk because an attacker did not require a valid account, administrator privileges or user interaction. A specially prepared anonymous request could exploit weaknesses in the WordPress REST API and potentially run arbitrary code on the underlying server.

Successful exploitation could give an intruder control over a website, its database and stored information. Attackers could alter pages, steal credentials, implant malicious software, redirect visitors or use compromised servers to launch further attacks.

WordPress activated forced updates through its automatic-update system because of the severity of the issue. Websites that support automatic background updates should receive the patched release, although administrators have been advised to verify the version installed rather than assume the process has completed successfully.

The vulnerability arose from confusion in the handling of REST API batch routes, combined with an SQL injection condition that could lead to remote code execution. The affected component allows multiple REST API requests to be processed together, improving efficiency for applications interacting with WordPress.

Security researcher Adam Kues, working with Assetnote and Searchlight Cyber, identified the flaw and reported it privately so that fixes could be prepared before technical details were made public. The issue was assigned a critical severity rating because exploitation was possible over a network with low complexity and without authentication.

A stock WordPress installation could be vulnerable even when no third-party themes or plugins were installed. That characteristic distinguishes wp2shell from many widespread WordPress compromises, which commonly exploit poorly maintained extensions rather than the platform’s core software.

WordPress 6.9 was affected by both the critical remote-code-execution vulnerability and a separate high-severity SQL injection flaw, tracked as CVE-2026-60137. Version 6.9.5 contains fixes for both issues. WordPress 6.8 was affected only by the separate SQL injection problem and has been patched through version 6.8.6.

Versions released before WordPress 6.8 are not affected by either of the newly disclosed vulnerabilities. However, operators using older branches still face security risks arising from unsupported software and previously disclosed flaws. WordPress maintains that only its newest release receives full active support.

The beta version of WordPress 7.1 was also affected. Developers and testing teams using that branch have been directed to move to WordPress 7.1 Beta 2, which includes the required fixes. Production websites are not supposed to run beta software.

The update modifies three core files connected to REST API processing and database queries: class-wp-rest-server. php, class-wp-query. php and rest-api. php. No WordPress packages were revised as part of the security release.

WordPress is used across a vast range of websites, from personal blogs and small businesses to news platforms, online shops and government portals. Estimates place its global footprint at hundreds of millions of sites, magnifying the potential impact of a core vulnerability that can be exploited without credentials.

Website owners should confirm that their installations now show WordPress 7.0.2, 6.9.5 or another unaffected version. Administrators running the 6.8 branch should upgrade to at least 6.8.6 because of the accompanying SQL injection fix.

Operators unable to update automatically can install the release through the Dashboard’s Updates section. Managed hosting customers should verify whether their provider has applied the patch, particularly when update controls are handled centrally.

Security teams have also advised administrators to examine server access logs, unexpected administrator accounts, unfamiliar scheduled tasks and changes to core files. Unexplained redirects, injected scripts or newly created PHP files may indicate compromise.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Russia brings cryptocurrency market law into force // India plans own orbital space outpost, second after China // Haldwani purification row: Caste back on political centre-stage // Amicura X1 Max Smart Cat Litter Box:AliExpress France Official Warehouse, Litter Box at One Click // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // Hong Kong Ranks Fifth Among APAC’s Preferred Living Investment Destinations as 85% of Investors Plan to Increase Sector Investment // Alpha Dhabi lifts MICAD commitment to $1 billion // Ingdan, Inc. (400.HK) Announces 2026 Interim Results // WisPaper Introduces TrueCite to Help Researchers Verify AI-Generated Academic References // The Mineral Boutique Limited Welcomes CCS Clarification and Reaffirms Asia Growth Strategy // Putin holds talks with Pezeshkian in Bishkek // Venezuela defends sovereignty after Trump oil control claim // Trump rejects munitions fears as Iran clashes resume // Adobe widens Saudi AI access with $4 billion programme // XcanMow Mix 2000 Robot Mower Makes Its European Debut at IFA Berlin 2026 // LatAm gushers and possible Venezuela exit a nightmare for Opec // Best Mart 360 Reports Interim Revenue Growth to HK$1.45 billion // Dubai hotel provides free public co-working space // Macao Economic, Trade, and Tourism Investment Promotion Seminar Convened in Jakarta, Indonesia, Fostering Multi-Dimensional Cooperation to Jointly Explore New Opportunities Along the Silk Road // What Shein’s $27bn IPO means for Mubadala //