logo

WP2Shell Technical Analysis: CVE-2026-63030 & CVE-2026-60137 WordPress Core RCE Chain

ID: 76cdb20d-baad-51dc-8bf7-23cc2b5eb087

STIX ID: report--76cdb20d-baad-51dc-8bf7-23cc2b5eb087

Feed Name: Brandefense Blog

Threat Score
90/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: İlda Ersezer

...
...

WP2Shell is a critical unauthenticated remote-code-execution chain in WordPress Core that combines a REST batch route confusion (CVE-2026-63030) with a WP_Query SQL injection (CVE-2026-60137). The chain allows a single unauthenticated POST to /wp-json/batch/v1 (or ?rest_route=/batch/v1) to bypass authentication, exploit SQLi, escalate to admin context, create an admin user, and execute arbitrary PHP; public PoC and active exploitation were observed within hours of disclosure. Affected versions include WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1 (patches: 6.9.5/7.0.2/6.8.6), and the report includes detection patterns, database and filesystem IoCs, mitigation steps, and a post-compromise recovery checklist.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.