wp2shell: A Pre-Authentication RCE in WordPress Core, and Why It Is an Exposure Validation Problem
ID: 5a8a3dd2-278d-592a-bc89-630b2d6859ae
STIX ID: report--5a8a3dd2-278d-592a-bc89-630b2d6859ae
Feed Name: Security Boulevard
On July 17, 2026 researchers disclosed "wp2shell", a pre-authentication RCE in WordPress Core that chains a SQL injection in the author__not_in parameter (CVE-2026-60137) with a REST API batch route confusion (/wp-json/batch/v1, CVE-2026-63030), affecting default installs of WordPress (6.9.0–6.9.4 and 7.0.0–7.0.1). Patches were released (6.9.5 and 7.0.2) and forced auto-updates were applied; the advisory urges immediate patching, verification of every internet-facing instance, temporary mitigation of the batch endpoint if patching is delayed, and forensic checks if compromise is plausible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
