Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-63030 & CVE-2026-60137: WordPress Core Pre-Authentication RCE Overview & Takeaways

Summary

The wp2shell chain pairs REST API route confusion (CVE-2026-63030) with WP_Query SQL injection (CVE-2026-60137) for unauthenticated full RCE on WordPress Core, now actively exploited in the wild.
Published
Collected

original ↗