Rescana
Critical wp2shell Vulnerability Enables Unauthenticated RCE in WordPress
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A critical vulnerability chain, dubbed wp2shell, has been identified in WordPress Core, allowing unauthenticated attackers to execute arbitrary code on default installations. This vulnerability is tracked as CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection). Exploitation can occur via a single anonymous HTTP request, impacting WordPress versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. Security teams are urging immediate updates to versions 6.9.5 and 7.0.2 to mitigate risks. A public proof-of-concept (PoC) is available, and while no mass exploitation has been confirmed, the risk is considered extremely high. The vulnerabilities were disclosed on July 17, 2026, and have been actively discussed in the security community.
Key Points: • The wp2shell vulnerability allows unauthenticated remote code execution on WordPress installations. • Affected versions include WordPress 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1, with patches available. • Immediate updates are recommended due to the critical nature of the vulnerabilities and available exploit code.