Wp2shell cPFence plugin protection

A critical vulnerability in WordPress Core, known as wp2shell, affects:

  • WordPress 6.9.0–6.9.4
  • WordPress 7.0.0–7.0.1
  • WordPress 7.1 Beta 1

The official fixes are included in WordPress 6.9.5, 7.0.2, and 7.1 Beta 2.

For older WordPress installations that cannot be upgraded at the moment, cPFence has released a free standalone plugin that blocks the malformed REST API batch requests used by the vulnerability.

Download the plugin:

https://gist.githubusercontent.com/cPFence/e574db54e99bb03bfe0d4217d32d8515/raw/cpfence-wp2shell-mitigation.php

Save the file as:

cpfence-wp2shell-mitigation.php

Then upload it to:

wp-content/plugins/cpfence-wp2shell-mitigation/

Activate it from Plugins in WordPress.

If you are using cPFence, you can deploy the plugin ZIP across selected or all websites on all servers using cPFence’s bulk plugin installation tools. Simply zip the file, upload it, and click “Bulk Install Plugin”:

More info:

https://my.cpfence.app/knowledgebase/154/How-to-bulk-Install-a-WordPress-Plugin-Slug-or-ZIP-using-cPFence-Tools.html

This plugin is only a temporary mitigation. Update WordPress Core as soon as possible, then deactivate and remove the plugin.

DISCLAIMER
 ----------
This plugin is a temporary mitigation, not a replacement for the official
WordPress security update. Back up your site and test this plugin in a
staging environment before using it in production. It is provided "as is",
without warranty of any kind. Linkers Gate LLC and the cPFence.app Team are
not liable for site downtime, incompatibilities, data loss, security
incidents, or other damages arising from its use.

Comments are disabled