WordPress Core “wp2shell” RCE flaws get public exploits, patch now

WordPress Core “wp2shell” RCE flaws get public exploits, patch now
Public proof-of-concept exploits have been released for the wp2shell vulnerabilities in WordPress Core, enabling pre-authentication remote code execution against affected installations. Administrators should patch immediately to WordPress 7.0.2 or 6.9.5, as in-the-wild exploitation has already been observed. #wp2shell #CVE-2026-63030 #CVE-2026-60137 #WordPress

Keypoints

  • wp2shell is a chained exploit affecting WordPress Core.
  • The flaws are tracked as CVE-2026-63030 and CVE-2026-60137.
  • The attack can lead to unauthenticated remote code execution on WordPress 6.9.x and 7.0.x.
  • WordPress has forced automatic security updates and recommends version 7.0.2 or 6.9.5.
  • Public PoC exploits are circulating, and signs of in-the-wild exploitation have been reported.

Read More: https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/