Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits
ID: ddcc547a-f52a-54cb-bbac-1baeb3591269
STIX ID: report--ddcc547a-f52a-54cb-bbac-1baeb3591269
Feed Name: Security Affairs
Public proof-of-concept exploits were released for two critical WordPress Core flaws (CVE-2026-63030 — REST API batch-route confusion, and CVE-2026-60137 — SQL injection in author__not_in) that can be chained to achieve unauthenticated remote code execution on WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1. WordPress issued emergency security releases (update to 7.0.2 or 6.9.5) and enabled forced auto-updates; administrators unable to patch immediately are advised to block anonymous access to the REST batch endpoints as a temporary mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
