A critical vulnerability in WordPress Core, known as wp2shell, affects:
- WordPress 6.9.0–6.9.4
- WordPress 7.0.0–7.0.1
- WordPress 7.1 Beta 1
The official fixes are included in WordPress 6.9.5, 7.0.2, and 7.1 Beta 2.
For older WordPress installations that cannot be upgraded at the moment, cPFence has released a free standalone plugin that blocks the malformed REST API batch requests used by the vulnerability.
Download the plugin:
Save the file as:
cpfence-wp2shell-mitigation.php
Then upload it to:
wp-content/plugins/cpfence-wp2shell-mitigation/
Activate it from Plugins in WordPress.
If you are using cPFence, you can deploy the plugin ZIP across selected or all websites on all servers using cPFence’s bulk plugin installation tools. Simply zip the file, upload it, and click “Bulk Install Plugin”:
More info:
This plugin is only a temporary mitigation. Update WordPress Core as soon as possible, then deactivate and remove the plugin.
DISCLAIMER ---------- This plugin is a temporary mitigation, not a replacement for the official WordPress security update. Back up your site and test this plugin in a staging environment before using it in production. It is provided "as is", without warranty of any kind. Linkers Gate LLC and the cPFence.app Team are not liable for site downtime, incompatibilities, data loss, security incidents, or other damages arising from its use.

