logo

WordPress vulnerabilities (wp2shell): Find impacted instances

ID: 18a8cf0f-df92-5daf-93ba-9b9cc0d42ce4

STIX ID: report--18a8cf0f-df92-5daf-93ba-9b9cc0d42ce4

Feed Name: runZero Blog

Threat Score
75/100

Date Published: 2026-07-18

Date Updated: 2026-07-19

Author: Cale Black

...
...

Critical WordPress vulnerabilities (CVE-2026-60137 and CVE-2026-63030, collectively referred to as "wp2shell") were disclosed with a CVSS score of 9.8; successful exploitation may allow unauthenticated SQL injection and remote code execution. Administrators are urged to upgrade to WordPress 6.9.5 / 7.0.2 / 7.1 Beta 2 or later; a runZero query is provided to find potentially impacted systems.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.