WordPress 6.9.0u20136.9.4 and 7.0.0u20137.0.1 fail to add a placeholder to the batch handler’s $matches array when a REST sub-request errors, desynchronising it from the validation array so a later sub-request runs with the wrong route’s permission callback. Chained with the companion author_exclude SQL injection (CVE-2026-60137), an unauthenticated attacker can escalate to administrator and reach pre-auth Remote Code Execution (“wp2shell”).

This vulnerability affects the following application versions:

  • WordPress 6.8
  • WordPress 6.8.1
  • WordPress 6.8.2
  • WordPress 6.8.3
  • WordPress 6.8.4
  • WordPress 6.8.5
  • WordPress 6.9
  • WordPress 6.9.1
  • WordPress 6.9.2
  • WordPress 6.9.3
  • WordPress 6.9.4
  • WordPress 7.0
  • WordPress 7.0.1

Skriv et svar

Din e-mailadresse vil ikke blive publiceret. Krævede felter er markeret med *