CVE-2026-63030 and CVE-2026-60137 (wp2shell): WordPress RCE Explained
ID: 2802ad28-f2af-5e82-bf53-3a86b2b34c82
STIX ID: report--2802ad28-f2af-5e82-bf53-3a86b2b34c82
Feed Name: Resources-2
Threat Score
**wp2shell (CVE-2026-63030 & CVE-2026-60137)** describes an unauthenticated remote-code-execution chain in WordPress core that abuses a route-confusion bug in the batch REST endpoint to produce SQL injection, craft poisoned WP_Post objects via object hydration and oEmbed caching, and perform nested saves to forge an administrator account—allowing attackers to install plugins and achieve full code execution on default WordPress installations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
