[CVE-2026-63030] Now Detecting: WP2Shell - Pre-Authentication RCE in WordPress Core
ethiack.com | vulnerability | Critical | CVE-2026-63030 | #rce | #zero-day | #rest-api | #sql-injection | #wordpress | #waf | #vulnerability | #ethiack | #cve-2026-63030
Summary
WP2Shell (CVE-2026-63030/CVE-2026-60137) is an unauthenticated WordPress Core RCE chaining a REST API batch-route confusion with SQL injection; Ethiack details patches, mitigations, and detection.
- Vendor
- WordPress
- Product
- WordPress Core
- Affected versions
- WordPress 6.9.0-6.9.4 and 7.0.0-7.0.1; fixed in 6.9.5 and 7.0.2
- Published
- Collected
Skip to content