[CVE-2026-63030] Unauthenticated RCE in WordPress core (wp2shell), via SQL injection
aikido.dev | vulnerability | Critical | CVE-2026-63030 | #rce | #featured | #vulnerability-research | #rest-api | #sql-injection | #wordpress | #vulnerability | #cve | #wp2shell
Summary
WP2Shell chains CVE-2026-63030 in WordPress REST batch routing with the CVE-2026-60137 SQL-injection primitive to achieve pre-authentication remote code execution on stock WordPress installations. Versions 6.9.5 and 7.0.2 contain the fixes.
Why it matters
WP2Shell chains a WordPress core REST routing flaw with SQL injection into pre-authentication RCE on stock installations. Affected sites should move immediately to 6.9.5 or 7.0.2.
- Vendor
- WordPress
- Product
- WordPress Core
- Affected versions
- WordPress 6.9.0-6.9.4 and 7.0.0-7.0.1; fixed in 6.9.5 and 7.0.2
- Published
- Collected
Skip to content