logo

Critical wp2shell Vulnerability Hits WordPress Core, Patch Released

ID: 240958f4-e71e-5871-b865-98d6a6b54004

STIX ID: report--240958f4-e71e-5871-b865-98d6a6b54004

Feed Name: The Cyber Express

Threat Score
78/100

Date Published: 2026-07-30

Date Updated: 2026-07-30

Author: Ashish Khaitan

...
...

WordPress patched a critical RCE vulnerability dubbed "wp2shell" (CVE-2026-63030) that allowed anonymous remote code execution via the REST API batch endpoint and also fixed a separate critical SQL injection (CVE-2026-60137); affected versions were updated in WordPress 6.9.5 and 7.0.2, forced auto-updates were enabled for vulnerable releases, and administrators are urged to apply patches or temporarily block the batch endpoints at the WAF level because exploitation requires no authentication and could impact a large proportion of internet sites.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.