CVE-2026-63030 & CVE-2026-60137: WordPress Core Pre-Authentication RCE Overview & Takeaways
netspi.com | vulnerability | #rce | #wordpress | #sqli | #cve-2026-63030 | #cve-2026-60137 | #in-the-wild | #patch-now
Summary
The wp2shell chain pairs REST API route confusion (CVE-2026-63030) with WP_Query SQL injection (CVE-2026-60137) for unauthenticated full RCE on WordPress Core, now actively exploited in the wild.
- Published
- Collected
Skip to content