bleeping-computer · Crawled Jul 18, 2026

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

1 IoCs
Read original article ↗

AI Summary

Critical remote code execution vulnerabilities in WordPress Core, collectively known as 'wp2shell' and tracked as CVE-2026-63030 and CVE-2026-60137, have been publicly exploited. These flaws allow unauthenticated attackers to execute arbitrary code on affected WordPress installations running versions 6.9.0–6.9.4 and 7.0.0–7.0.1. The vulnerabilities stem from a REST API batch-route confusion flaw and a SQL injection in the 'author__not_in' parameter, which can be chained together for pre-authentication RCE. Immediate patching to WordPress 7.0.2 or 6.9.5 is strongly advised due to active exploitation.

AI-extracted · verify before operational use

Indicators of Compromise 1 extracted

Type Value Detail
Domain wp2shell[.]com Details →