WordPress Core "wp2shell" RCE flaws get public exploits, patch now
PoC publicWordPress CoreOur summary
Public proof-of-concept exploits have emerged for the critical 'wp2shell' remote code execution vulnerabilities in WordPress Core, urging immediate action from site administrators. The vulnerabilities, CVE-2026-63030 and CVE-2026-60137, allow unauthenticated attackers to execute arbitrary code on affected installations running versions 6.9.x and 7.0.x. These flaws can be exploited without prior authentication and affect default setups with no additional plugins required. The WordPress security team has activated forced auto-updates to address the issue, recommending users upgrade to version 7.0.2 or 6.9.5 as soon as possible.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.