WordPress Core "wp2shell" RCE flaws get public exploits, patch now - BleepingComputer

What the report says
BleepingComputer reports that public proof-of-concept exploits have been released for critical WordPress Core vulnerabilities known as “wp2shell,” increasing pressure on administrators to apply security updates immediately. The issues are tracked as CVE-2026-63030 and CVE-2026-60137 and can reportedly be combined to achieve pre-authentication remote code execution on affected WordPress 6.9.x and 7.0.x installations. The flaws were found by Adam Kues of Searchlight Cyber, which said the attack can work against a default WordPress site without plugins or prior authentication.
According to the report, WordPress has issued fixes in versions 6.9.5 and 7.0.2 and enabled forced automatic security updates for supported affected installations because of the severity. WordPress advisories cited by BleepingComputer say the full remote code execution chain affects versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. A related SQL injection issue also affects WordPress 6.8.0 through 6.8.5, but BleepingComputer reports it cannot be chained to remote code execution there because the second flaw was introduced later.
Searchlight Cyber has withheld deeper technical details while offering a website for administrators to check exposure. For organizations that cannot patch immediately, it suggested temporary controls such as blocking anonymous REST API access or filtering specific batch endpoints at a web application firewall. Cloudflare also said it deployed WAF protections for both vulnerabilities across its plans, while emphasizing that filtering should not replace updates.
BleepingComputer says multiple exploit examples are now available on GitHub, and security firm watchTowr reported early signs of exploitation in the wild. The development matters because WordPress is widely used, making core vulnerabilities with public exploit code a potentially broad risk for website operators.
Loading debate for this article…
Other publishers covering this story
No additional verified coverage is currently clustered with this report.

Tracy Melon calls for removal of AI versions of artistes’ songsSqoop Uganda
Al‑Qaida and the Islamic State are both adopting AIThe Independent Uganda
Apple adds 37 hardware identifiers ahead of ‘Surprise and Shine’ event - 9to5Mac9to5Mac
Apple wanted the iPhone Ultra to cost $1,999, new report says - GSMArena.com news - GSMArena.comGSMArena.com
LG TV shown scanning LAN for third-party phones and other devices - Ars TechnicaArs Technica
GOG brings back "big box" PC games, one printable template at a time - Ars TechnicaArs Technica