WordPress core pre-auth RCE flaw
Vulnerability
Updated: 18.07.2026 00:20
· First: 18.07.2026 00:20
· 📰 1 src / 1 articles
· H score: 48
WordPress core had a pre-auth RCE that affected default installs and let an anonymous HTTP request run code. 6.9.5 and 7.0.2 fixed the issue on July 17, 2026, covering 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. The flaw was reachable in core with no plugins required, so exposed sites faced direct remote code-execution risk until patched.