256 Newsroom — Uganda's Digital News Infrastructure
Consumer Technology

WordPress Core "wp2shell" RCE flaws get public exploits, patch now - BleepingComputer

Share
WordPress Core "wp2shell" RCE flaws get public exploits, patch now - BleepingComputer
Image · BleepingComputer

What the report says

BleepingComputer reports that public proof-of-concept exploits have been released for critical WordPress Core vulnerabilities known as “wp2shell,” increasing pressure on administrators to apply security updates immediately. The issues are tracked as CVE-2026-63030 and CVE-2026-60137 and can reportedly be combined to achieve pre-authentication remote code execution on affected WordPress 6.9.x and 7.0.x installations. The flaws were found by Adam Kues of Searchlight Cyber, which said the attack can work against a default WordPress site without plugins or prior authentication.

According to the report, WordPress has issued fixes in versions 6.9.5 and 7.0.2 and enabled forced automatic security updates for supported affected installations because of the severity. WordPress advisories cited by BleepingComputer say the full remote code execution chain affects versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. A related SQL injection issue also affects WordPress 6.8.0 through 6.8.5, but BleepingComputer reports it cannot be chained to remote code execution there because the second flaw was introduced later.

Searchlight Cyber has withheld deeper technical details while offering a website for administrators to check exposure. For organizations that cannot patch immediately, it suggested temporary controls such as blocking anonymous REST API access or filtering specific batch endpoints at a web application firewall. Cloudflare also said it deployed WAF protections for both vulnerabilities across its plans, while emphasizing that filtering should not replace updates.

BleepingComputer says multiple exploit examples are now available on GitHub, and security firm watchTowr reported early signs of exploitation in the wild. The development matters because WordPress is widely used, making core vulnerabilities with public exploit code a potentially broad risk for website operators.

Read the full report at BleepingComputer →

Loading debate for this article…

Other publishers covering this story

No additional verified coverage is currently clustered with this report.

Related reporting