← Back to blog

Critical WordPress Core RCE Flaw Affects All 6.9 and 7.0 Sites

A newly disclosed unauthenticated remote code execution flaw impacts core WordPress installations. All sites running versions 6.9 and 7.0 are vulnerable.

TL;DR

  • CVE-2026-2224 and CVE-2026-2225 allow unauthenticated RCE in WordPress core
  • All 6.9 and 7.0 sites are affected regardless of plugins
  • Attackers can execute code via anonymous HTTP requests
  • Persistent object cache configurations may influence exploitability
  • Immediate update to patched versions is strongly recommended

A critical security vulnerability has been discovered in WordPress core that allows unauthenticated attackers to execute arbitrary code on affected websites. The flaw impacts all WordPress installations running versions 6.9 and 7.0, meaning even sites with no plugins installed are potentially exploitable.

Security researchers have confirmed that the vulnerability can be triggered through anonymous HTTP requests, making it particularly dangerous as no authentication is required to exploit it. The issue has been assigned two CVE identifiers and a working proof-of-concept has been made public, increasing the urgency for site administrators to take immediate action.

Vulnerability Details

  • The flaw resides in WordPress core functionality, making all 6.9 and 7.0 installations vulnerable by default
  • Two separate CVEs (CVE-2026-2224 and CVE-2026-2225) have been assigned to the issues
  • No authentication required - attackers can exploit the vulnerability anonymously
  • Even minimal WordPress installations without any plugins are affected
  • Persistent object cache configurations may affect how the vulnerability manifests

Impact and Recommendations

  • All WordPress sites running versions 6.9 and 7.0 should be considered compromised if not yet patched
  • A public proof-of-concept exploit exists, increasing the likelihood of active exploitation
  • Site administrators should immediately update to the latest patched WordPress version
  • Organizations should audit their WordPress installations for signs of compromise
  • Consider implementing temporary web application firewall rules if immediate patching isn't possible

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

Critical WordPress Core RCE Flaw Affects All 6.9 and 7.0 Sites — Agent Breach Blog | Agent Breach