logo

wp2shell: A Pre-Authentication RCE in WordPress Core, and Why It Is an Exposure Validation Problem

ID: 5a8a3dd2-278d-592a-bc89-630b2d6859ae

STIX ID: report--5a8a3dd2-278d-592a-bc89-630b2d6859ae

Feed Name: Security Boulevard

Threat Score
88/100

Date Published: 2026-07-18

Date Updated: 2026-07-18

Author: Strobes Security

...
...

On July 17, 2026 researchers disclosed "wp2shell", a pre-authentication RCE in WordPress Core that chains a SQL injection in the author__not_in parameter (CVE-2026-60137) with a REST API batch route confusion (/wp-json/batch/v1, CVE-2026-63030), affecting default installs of WordPress (6.9.0–6.9.4 and 7.0.0–7.0.1). Patches were released (6.9.5 and 7.0.2) and forced auto-updates were applied; the advisory urges immediate patching, verification of every internet-facing instance, temporary mitigation of the batch endpoint if patching is delayed, and forensic checks if compromise is plausible.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.