logo

Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details

ID: dd30a7d6-cca4-5dd1-9962-9131e31249b7

STIX ID: report--dd30a7d6-cca4-5dd1-9962-9131e31249b7

Feed Name: cybersecurityNews.com

Threat Score
95/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Guru Baran

...
...

A critical pre-authentication remote code execution chain named "wp2shell" affecting WordPress (combining CVE-2026-63030 and CVE-2026-60137) enables unauthenticated full server compromise on stock installations; the report details AI-assisted discovery, a step-by-step technical exploit chain, impacted versions, active public PoCs and in-the-wild exploitation, and urges immediate patching to fixed releases (6.8.6, 6.9.5, 7.0.2).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.