Critical wp2shell Vulnerability Enables Unauthenticated RCE in WordPress

Critical wp2shell Vulnerability Enables Unauthenticated RCE in WordPress

First seen 20 Jul 2026, 11:05 UTC ThehackernewsRescanaTenableTechnaduCybernews+17 86% similarity 72.9

Article Content

Browse articles
ThreatCluster

A critical vulnerability chain, dubbed wp2shell, has been identified in WordPress Core, allowing unauthenticated attackers to execute arbitrary code on default installations. This vulnerability is tracked as CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection). Exploitation can occur via a single anonymous HTTP request, impacting WordPress versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. Security teams are urging immediate updates to versions 6.9.5 and 7.0.2 to mitigate risks. A public proof-of-concept (PoC) is available, and while no mass exploitation has been confirmed, the risk is considered extremely high. The vulnerabilities were disclosed on July 17, 2026, and have been actively discussed in the security community.

Key Points: • The wp2shell vulnerability allows unauthenticated remote code execution on WordPress installations. • Affected versions include WordPress 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1, with patches available. • Immediate updates are recommended due to the critical nature of the vulnerabilities and available exploit code.

ThreatCluster AI

Timeline

2026-07-17
CVE-2026-63030 and CVE-2026-60137 disclosed
WordPress released security updates addressing the wp2shell vulnerabilities, enabling forced updates for affected versions.
Tenable
2026-07-18
First public PoC for CVE-2026-63030 released
A public proof-of-concept demonstrating the exploitation of the REST API batch-route confusion vulnerability was made available.
Tenable
2026-07-19
First public PoC for CVE-2026-60137 released
A public proof-of-concept for the SQL injection component of the wp2shell vulnerability chain was published.
Tenable
2026-07-20
Security teams urge immediate updates
Organizations are advised to update to WordPress versions 6.9.5 or 7.0.2 to mitigate the wp2shell vulnerabilities.
Cybernews

Community

Browse all →