WP2Shell (CVE-2026-63030/CVE-2026-60137) is an unauthenticated WordPress Core RCE chaining a REST API batch-route confusion with SQL injection; Ethiack details patches, mitigations, and detection.
WP2Shell chains CVE-2026-63030 in WordPress REST batch routing with the CVE-2026-60137 SQL-injection primitive to achieve pre-authentication remote code execution on stock WordPress installations. Versions 6.9.5 and 7.0.2 contain the fixes.
Why it matters: WP2Shell chains a WordPress core REST routing flaw with SQL injection into pre-authentication RCE on stock installations. Affected sites should move immediately to 6.9.5 or 7.0.2.