logo

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

ID: eeb5f7a8-3108-5643-a734-a1044c1ca412

STIX ID: report--eeb5f7a8-3108-5643-a734-a1044c1ca412

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

Author: Lawrence Abrams

...
...

Public proof-of-concept exploits have been released for two chained WordPress Core vulnerabilities (CVE-2026-63030 and CVE-2026-60137) that allow pre-authentication remote code execution against WordPress 6.9.x and 7.0.x; administrators are urged to update immediately to WordPress 7.0.2 or 6.9.5, or apply temporary mitigations such as blocking /wp-json/batch/v1 or using WAF protections while patches are applied.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.