logo

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

ID: 65671c42-e810-5210-b060-ec4a50bccc5d

STIX ID: report--65671c42-e810-5210-b060-ec4a50bccc5d

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-07-17

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

Updated July 18, 2026 — Two WordPress core flaws (CVE-2026-63030 and CVE-2026-60137) can be chained by an anonymous request to achieve unauthenticated remote code execution on default installs of WordPress 6.9.x and 7.0.x (the SQL injection also affects 6.8.x). The chain is public, a working proof-of-concept and exploit were published, patches were released (6.8.6, 6.9.5, 7.0.2), and mitigations include blocking the /wp-json/batch/v1 and rest_route=/batch/v1 endpoints at a WAF, disabling unauthenticated REST access, or applying short-term plugin-based dispatch checks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.