logo

wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

ID: dbd425d8-2cf0-50e8-ac84-4aa2c653e6e8

STIX ID: report--dbd425d8-2cf0-50e8-ac84-4aa2c653e6e8

Feed Name: Tenable Blog

Threat Score
85/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

Author: Satnam Narang

...
...

wp2shell is a critical two-vulnerability chain in WordPress Core (CVE-2026-63030 and CVE-2026-60137) that enables unauthenticated remote code execution on WordPress 6.9.x and 7.0.x; public PoCs and confirmed in-the-wild exploitation appeared within hours of disclosure on July 17, 2026, and patches are available (6.9.5, 7.0.2) with forced automatic updates enabled for supported installations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.