Hackers Already Exploiting Newly Patched WordPress Flaws, Researchers Warn
ID: cdebb380-b190-5e71-bc8c-d074496b5541
STIX ID: report--cdebb380-b190-5e71-bc8c-d074496b5541
Feed Name: TechRepublic Security
Threat Score
**WP2Shell** — Two chained WordPress Core vulnerabilities (CVE-2026-63030: critical Batch REST API flaw, and CVE-2026-60137: SQL injection) enable pre-auth remote code execution allowing full takeover of vulnerable sites; patches have been released and automatic updates enabled, but security firms report active exploitation and millions of potentially exposed installations, so site owners are urged to apply updates immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
