CVE Tools

Опубликованы эксплоиты для критической проблемы в ядре WordPress

Хакер (xakep.ru)By Мария Нефёдова

PoC publicWordPress core

Our summary

Proof-of-concept (PoC) exploits have been published for a critical vulnerability chain in the WordPress core, known as wp2shell. These flaws allow unauthenticated attackers to execute arbitrary code on clean WordPress installations without requiring additional plugins. Security researchers have already observed signs of real-world exploitation attempts. The vulnerability consists of two separate issues: CVE-2026-63030, introduced in WordPress 6.9 and related to the REST API batch endpoint, and CVE-2026-60137, an SQL injection flaw in the WP_Query class affecting versions starting from 6.8. Patches were included in WordPress 6.9.5, 7.0.2, and 7.1 beta 2. Administrators are urged to update immediately to prevent potential attacks.

Read at Хакер (xakep.ru)

Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store