logo

Critical WordPress wp2shell Flaw Lets Anonymous Attackers Execute Remote Code

ID: 77335e3c-af7c-51d4-a76a-1e6f7d76d49c

STIX ID: report--77335e3c-af7c-51d4-a76a-1e6f7d76d49c

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

Author: Tamilselvan

...
...

**Critical pre-auth RCE 'wp2shell' in WordPress Core:** A pre-auth remote code execution vulnerability (and an associated facilitated SQL injection) affecting multiple recent WordPress releases was disclosed, tracked by CVE-2026-60137 and CVE-2026-63030. WordPress released 7.0.2 and backports (6.9.5, 6.8.6, 7.1 beta2) and enabled forced automatic updates; site owners are urged to patch immediately or apply temporary REST API/WAF mitigations while proof-of-concept details remain withheld.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.