WordPress 6.9.0u20136.9.4 and 7.0.0u20137.0.1 fail to add a placeholder to the batch handler’s $matches array when a REST sub-request errors, desynchronising it from the validation array so a later sub-request runs with the wrong route’s permission callback. Chained with the companion author_exclude SQL injection (CVE-2026-60137), an unauthenticated attacker can escalate to administrator and reach pre-auth Remote Code Execution (“wp2shell”).
This vulnerability affects the following application versions:
- WordPress 6.8
- WordPress 6.8.1
- WordPress 6.8.2
- WordPress 6.8.3
- WordPress 6.8.4
- WordPress 6.8.5
- WordPress 6.9
- WordPress 6.9.1
- WordPress 6.9.2
- WordPress 6.9.3
- WordPress 6.9.4
- WordPress 7.0
- WordPress 7.0.1