Back to news

WordPress Core RCE Bug and Microsoft's 570-Flaw Patch Drop Demand Urgent Action

Two major patch events hit simultaneously: a no-authentication WordPress remote code execution flaw and Microsoft's largest-ever Patch Tuesday by a wide margin.

WordPress Core RCE Bug and Microsoft's 570-Flaw Patch Drop Demand Urgent Action

What happened

A critical remote code execution vulnerability, tracked as wp2shell, was disclosed in WordPress core, meaning any site running versions 6.9 or 7.0 was exploitable by an unauthenticated attacker sending a plain HTTP request — no plugins or misconfigurations required. Researcher Adam Kues of Assetnote, the attack surface management division of Searchlight Cyber, discovered and responsibly reported the flaw. WordPress responded by releasing patched versions 6.9.5 and 7.0.2 on Friday and deploying forced automatic updates across its ecosystem. Separately, Microsoft issued fixes for 570 security vulnerabilities across Windows and related products in its latest Patch Tuesday — nearly triple the record it set just one month prior, with the company attributing the accelerated discovery rate to AI-assisted vulnerability research.

Why it matters for your business

The WordPress flaw sits in core, which means organizations that pride themselves on running lean, plugin-free installations had no inherent protection — a common but dangerous misconception. Any internet-facing WordPress deployment that has not yet applied the update or confirmed auto-update execution should be treated as potentially compromised and audited immediately. On the Microsoft side, a 570-vulnerability patch cycle stretches security and IT operations teams thin, raising the risk that high-severity items get buried beneath the volume. The practical takeaway is twofold: verify WordPress auto-updates actually fired and prioritize triage of Microsoft's release by CVSS score and exploitability ratings before end of the week.

What to watch next

Proof-of-concept exploit code for the WordPress flaw has not been confirmed publicly released, but the window between disclosure and weaponization is typically short for high-profile CMS vulnerabilities. Security teams should monitor threat intelligence feeds for active exploitation indicators over the coming days. On the Microsoft front, the trend of AI-accelerated vulnerability discovery suggests patch volumes will remain elevated or grow further, making automated patch management infrastructure less optional and more foundational.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp