A critical vulnerability in WordPress Core, known as wp2shell, affects:
WordPress 6.9.0–6.9.4
WordPress 7.0.0–7.0.1
WordPress 7.1 Beta 1
The official fixes are included in WordPress 6.9.5, 7.0.2, and 7.1 Beta 2.
For older WordPress installations that cannot be upgraded at the moment, cPFence has released a free standalone plugin that blocks the malformed REST API batch requests used by the vulnerability.
Download the plugin:
https://gist.githubusercontent.com/cPFence/e574db54e99bb03bfe0d4217d32d8515/raw/cpfence-wp2shell-mitigation.php
Save the file as:
cpfence-wp2shell-mitigation.php
Then upload it to:
wp-content/plugins/cpfence-wp2shell-mitigation/
Activate it from Plugins in WordPress.
If you are using cPFence, you can deploy the plugin ZIP across selected or all websites on all servers using cPFence’s bulk plugin installation tools. Simply zip the file, upload it, and click “Bulk Install Plugin”:

More info:
https://my.cpfence.app/knowledgebase/154/How-to-bulk-Install-a-WordPress-Plugin-Slug-or-ZIP-using-cPFence-Tools.html
This plugin is only a temporary mitigation. Update WordPress Core as soon as possible, then deactivate and remove the plugin.
DISCLAIMER
This plugin is a temporary mitigation, not a replacement for the official
WordPress security update. Back up your site and test this plugin in a
staging environment before using it in production. It is provided "as is",
without warranty of any kind. Linkers Gate LLC and the cPFence.app Team are
not liable for site downtime, incompatibilities, data loss, security
incidents, or other damages arising from its use.