wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
ID: dbd425d8-2cf0-50e8-ac84-4aa2c653e6e8
STIX ID: report--dbd425d8-2cf0-50e8-ac84-4aa2c653e6e8
Feed Name: Tenable Blog
Threat Score
wp2shell is a critical two-vulnerability chain in WordPress Core (CVE-2026-63030 and CVE-2026-60137) that enables unauthenticated remote code execution on WordPress 6.9.x and 7.0.x; public PoCs and confirmed in-the-wild exploitation appeared within hours of disclosure on July 17, 2026, and patches are available (6.9.5, 7.0.2) with forced automatic updates enabled for supported installations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
