logo

Critical wp2shell Vulnerability Enables Unauthenticated RCE in WordPress

ID: 9fb8900a-03db-51f0-85b2-7b4df735ef35

STIX ID: report--9fb8900a-03db-51f0-85b2-7b4df735ef35

Feed Name: ThreatCluster

Threat Score
90/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

...
...

A critical vulnerability chain dubbed "wp2shell" (CVE-2026-63030 and CVE-2026-60137) enables unauthenticated remote code execution against default WordPress installations (versions 6.9.0–6.9.4 and 7.0.0–7.0.1) via a single anonymous HTTP request; a public proof-of-concept exists and patches are available in versions 6.9.5 and 7.0.2, so immediate updates are recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.