Critical WordPress Core Flaw Lets Anonymous Hackers Gain Remote Code Execution
ID: 8f34a8ec-fc27-50fb-a22f-8ebf0deb5f85
STIX ID: report--8f34a8ec-fc27-50fb-a22f-8ebf0deb5f85
Feed Name: GBHackers
**Executive summary:** A critical pre-authentication remote code execution (RCE) vulnerability in WordPress Core dubbed wp2shell (CVE-2026-63030), paired with a related SQL injection (CVE-2026-60137), affects stock WordPress installations across multiple 6.9.x and 7.0.x releases; WordPress released patches (including 7.0.2, 6.9.5, 6.8.6), enabled forced auto-updates, and the advisory urges immediate patching, temporary REST API/WAF mitigations, and use of the wp2shell.com scanner to detect exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
