New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
ID: 65671c42-e810-5210-b060-ec4a50bccc5d
STIX ID: report--65671c42-e810-5210-b060-ec4a50bccc5d
Feed Name: The Hacker News
Updated July 18, 2026 — Two WordPress core flaws (CVE-2026-63030 and CVE-2026-60137) can be chained by an anonymous request to achieve unauthenticated remote code execution on default installs of WordPress 6.9.x and 7.0.x (the SQL injection also affects 6.8.x). The chain is public, a working proof-of-concept and exploit were published, patches were released (6.8.6, 6.9.5, 7.0.2), and mitigations include blocking the /wp-json/batch/v1 and rest_route=/batch/v1 endpoints at a WAF, disabling unauthenticated REST access, or applying short-term plugin-based dispatch checks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
