Critical wp2shell Vulnerability Hits WordPress Core, Patch Released
ID: 240958f4-e71e-5871-b865-98d6a6b54004
STIX ID: report--240958f4-e71e-5871-b865-98d6a6b54004
Feed Name: The Cyber Express
WordPress patched a critical RCE vulnerability dubbed "wp2shell" (CVE-2026-63030) that allowed anonymous remote code execution via the REST API batch endpoint and also fixed a separate critical SQL injection (CVE-2026-60137); affected versions were updated in WordPress 6.9.5 and 7.0.2, forced auto-updates were enabled for vulnerable releases, and administrators are urged to apply patches or temporarily block the batch endpoints at the WAF level because exploitation requires no authentication and could impact a large proportion of internet sites.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
