logo

CVE-2026-63030 and CVE-2026-60137 (wp2shell): WordPress RCE Explained

ID: 2802ad28-f2af-5e82-bf53-3a86b2b34c82

STIX ID: report--2802ad28-f2af-5e82-bf53-3a86b2b34c82

Feed Name: Resources-2

Threat Score
88/100

Date Published: 2026-07-20

Date Updated: 2026-07-22

Author: [email protected] (Umut Bayram)

...
...

**wp2shell (CVE-2026-63030 & CVE-2026-60137)** describes an unauthenticated remote-code-execution chain in WordPress core that abuses a route-confusion bug in the batch REST endpoint to produce SQL injection, craft poisoned WP_Post objects via object hydration and oEmbed caching, and perform nested saves to forge an administrator account—allowing attackers to install plugins and achieve full code execution on default WordPress installations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.