Unauthenticated Remote Code Execution Vulnerability Discovered in WordPress Core (wp2shell) Affects 6.9/7.0 Sites
What Happened — Researchers disclosed a core WordPress flaw (dubbed “wp2shell”) that allows any unauthenticated HTTP request to execute arbitrary code. The vulnerability affects fresh installations of WordPress 6.9 and 7.0 until the forced‑update releases 6.9.5 and 7.0.2 were deployed.
Why It Matters for Compliance & Audit Readiness
- Demonstrates the need for continuous vulnerability‑management controls (SOC 2 CC6.1 Risk Management, CC7.2 Change Management).
- Highlights the importance of maintaining auditable evidence of timely patching and forced‑update enforcement.
- Provides a concrete example of a control gap that can be mapped, monitored, and reported in a Trust Center dashboard.
Who Is Affected – Any organization running WordPress 6.9 or 7.0, spanning SaaS platforms, e‑commerce sites, media portals, and internal corporate sites.
Recommended Actions – Verify your WordPress version, apply the forced updates immediately, enable automatic core updates, integrate the site into your continuous vulnerability‑scanning program, and map the patch‑management process to SOC 2 controls for audit evidence. Source: The Hacker News
Technical Notes – The flaw is a server‑side request that triggers arbitrary PHP execution without authentication. No CVE number was published at the time of reporting; WordPress issued an advisory and released patched versions 6.9.5 and 7.0.2. Source: The Hacker News