Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2026-63030] Now Detecting: WP2Shell - Pre-Authentication RCE in WordPress Core

ethiack.com | vulnerability | Critical | CVE-2026-63030 | #rce | #zero-day | #rest-api | #sql-injection | #wordpress | #waf | #vulnerability | #ethiack | #cve-2026-63030

Summary

WP2Shell (CVE-2026-63030/CVE-2026-60137) is an unauthenticated WordPress Core RCE chaining a REST API batch-route confusion with SQL injection; Ethiack details patches, mitigations, and detection.
Vendor
WordPress
Product
WordPress Core
Affected versions
WordPress 6.9.0-6.9.4 and 7.0.0-7.0.1; fixed in 6.9.5 and 7.0.2
Published
Collected

original ↗

Related coverage

back