Warning: Critical, Actively Exploited Remote Code Execution in WordPress Core (CVE-2026-63030, CVE-2026-60137), Patch Immediately!
ID: 415e025c-85d3-5918-a7a2-05d38e761e83
STIX ID: report--415e025c-85d3-5918-a7a2-05d38e761e83
Feed Name: CCB Advisories Feed
Threat Score
WordPress Core vulnerabilities CVE-2026-63030 (critical REST API batch-route confusion allowing unauthenticated access) and CVE-2026-60137 (SQL injection) can be chained to achieve unauthenticated remote code execution (dubbed "wp2shell"). The advisory notes forced updates by WordPress, CISA inclusion in the Known Exploited Vulnerabilities catalogue, and recommends immediate patching, verification of updates, and enhanced monitoring for related suspicious activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
