HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Unauthenticated Remote Code Execution Vulnerability Discovered in WordPress Core (wp2shell) Affects 6.9/7.0 Sites

A core WordPress flaw (wp2shell) lets any unauthenticated HTTP request run arbitrary code on sites running 6.9 or 7.0. The issue underscores the need for continuous vulnerability‑management and auditable patch‑tracking in SOC 2 programs.

LiveThreat™ Intelligence · 📅 July 18, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
thehackernews.com

Unauthenticated Remote Code Execution Vulnerability Discovered in WordPress Core (wp2shell) Affects 6.9/7.0 Sites

What Happened — Researchers disclosed a core WordPress flaw (dubbed “wp2shell”) that allows any unauthenticated HTTP request to execute arbitrary code. The vulnerability affects fresh installations of WordPress 6.9 and 7.0 until the forced‑update releases 6.9.5 and 7.0.2 were deployed.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates the need for continuous vulnerability‑management controls (SOC 2 CC6.1 Risk Management, CC7.2 Change Management).
  • Highlights the importance of maintaining auditable evidence of timely patching and forced‑update enforcement.
  • Provides a concrete example of a control gap that can be mapped, monitored, and reported in a Trust Center dashboard.

Who Is Affected – Any organization running WordPress 6.9 or 7.0, spanning SaaS platforms, e‑commerce sites, media portals, and internal corporate sites.

Recommended Actions – Verify your WordPress version, apply the forced updates immediately, enable automatic core updates, integrate the site into your continuous vulnerability‑scanning program, and map the patch‑management process to SOC 2 controls for audit evidence. Source: The Hacker News

Technical Notes – The flaw is a server‑side request that triggers arbitrary PHP execution without authentication. No CVE number was published at the time of reporting; WordPress issued an advisory and released patched versions 6.9.5 and 7.0.2. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →