Until Friday, every WordPress 6.9 and 7.0 install on the internet could be handed over to a stranger with a single anonymous HTTP request. No login. No plugin vulnerability to chain. No social engineering. Just a bare, out-of-the-box WordPress core install and a bug researcher named Adam Kues who found it before someone with worse intentions did. This is the kind of story that should reset how IT teams think about cybersecurity: the biggest risk this week wasn’t a sophisticated nation-state operator, it was a stock install sitting there, waiting.

WordPress runs something like forty percent of the web. A remote-code-execution bug in core, not a theme, not a plugin, is about as close to a worst-case scenario as this ecosystem gets. And it landed in the same week that SonicWall’s edge appliances and Siemens’ OT switches both got walked from anonymous access to root through their own vulnerability chains. Three different products, three different layers of the stack, the same outcome. That pattern is the real story here.

An Anonymous Request Becomes Root, No Plugins Required

The flaw, now tracked publicly as wp2shell, lived in WordPress core itself. Assetnote, the attack surface management arm of Searchlight Cyber, found it and reported it responsibly. The result was bad enough that WordPress didn’t just ship a patch and post an advisory. It flipped on forced updates through its own auto-update system, pushing 6.9.5 and 7.0.2 to sites whether or not an admin had opted in.

Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system.

Think about what that forced push actually did. It quietly closed a hole on millions of sites whose owners will never know how close they came to a shell. That’s a genuinely good outcome, and it’s worth saying plainly: the auto-update system worked exactly as designed. But it only worked because WordPress core has the infrastructure to force a patch onto a site without asking permission. Most software doesn’t have that luxury, and a meaningful chunk of WordPress admins have that exact feature switched off because they’re scared of an update breaking a theme or a plugin.

The Pattern Repeats: SonicWall And Siemens Prove Root Is Root

Now compare that to the two other big vulnerability stories this week. SonicWall’s SMA mobile access appliances have two zero-days that, chained together, hand an attacker root-level capabilities. Inc Ransomware is already exploiting them in the wild. These aren’t theoretical. SMA appliances sit at the network edge by design, brokering remote access for entire organizations, which makes a root compromise there roughly equivalent to handing over the keys to the building.

Diagram illustrating a chained zero-day exploit path on Siemens ROX II OT switches
Unit 42’s analysis traces a three-step chain from initial access to persistent root on Siemens ROX II switches.

Then there’s Siemens ROX II. Unit 42 published a technical breakdown of three chained zero-days in these OT switches that together give an attacker privilege escalation and persistent root access. Operational technology gear like this often sits behind less monitoring, gets patched on a slower cycle, and in a lot of environments can’t be patched at all without a planned outage. A persistent root foothold on an OT switch isn’t a data breach risk. It’s a “someone can quietly sit on your industrial network for months” risk.

None of these three products, WordPress core, a VPN appliance, or an OT switch, have anything in common technically. What they share is the end state: anonymous or low-privilege access escalating all the way to root. That should be the takeaway from this week, not the individual CVEs. Attackers aren’t looking for exotic entry points. They’re looking for the shortest path to full control, and this week there were three of them sitting in plain sight across three completely different layers of infrastructure.

If You Turned Off Auto-Update, You Turned Off Your Safety Net

Cloudflare didn’t wait around either. In response to two other high-severity WordPress vulnerabilities disclosed by the WordPress security team, Cloudflare pushed WAF rules to protect customers running affected versions, while still telling everyone to patch. That’s the right instinct: a firewall rule buys you time, it doesn’t replace the fix. Treat every mitigation this week as a bridge to patching, not a substitute for it.

Cloudflare WAF dashboard showing new rules deployed for WordPress vulnerability protection
Cloudflare shipped WAF rules within hours of the WordPress disclosure, buying customers time to patch.

Here’s what actually moves the needle in your own environment this week:

  • Go check your WordPress install right now and confirm you’re on 6.9.5 or 7.0.2. If auto-update is disabled, ask yourself why, and if the answer isn’t a documented risk decision, turn it back on.
  • Patch or isolate every SonicWall SMA appliance immediately. If you can’t patch today, pull it off the open internet and restrict access by IP until you can.
  • Inventory your OT and industrial switches separately from your IT patch cycle. If Siemens ROX II is in your environment, get it on Unit 42’s advisory list and start the change-control process now, not after an outage window opens naturally.
  • Add or verify threat-protection and threat detection coverage at the edge, not just at the endpoint. Root-level compromises on appliances rarely trigger endpoint alerts because there’s no endpoint agent running on a VPN gateway or a switch.
  • Build security hardening and brute-force lockout policies into every internet-facing admin panel, including WordPress wp-admin, as a baseline, not an afterthought.

The bigger lesson for anyone doing cyber security planning this quarter is that you can’t rely on a single control to save you. WordPress got lucky because its vendor built forced updates into the product. SonicWall and Siemens customers don’t get that luxury, which means the burden falls back on your own defense in depth strategy: network segmentation, WAF rules, aggressive patch SLAs for anything internet-facing, and an incident response plan that assumes root-level compromise is the starting point of your investigation, not the worst-case scenario you hope never happens.

Three chains, three vendors, one week. That’s not a coincidence you can patch your way past. It’s a reminder that anonymous-to-root is still the most common shape an attack takes, and the products sitting quietly at your network edge are exactly where it keeps happening.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.