CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2848

As cited

Copy frozen at (site build).

vulnerabilities

wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve unauthenticated remote code execution on WordPress 6.9.x and 7.0.x installations. Active exploitation began within days of the July 17, 2026 disclosure, with public proof-of-concept code circulating and multiple security firms confirming attacks in the wild. Patches are available in WordPress 7.0.2 and 6.9.5, with WordPress.org enabling forced automatic updates for affected installations.

Why it matters: All WordPress administrators running versions 6.9.0 through 7.0.1 are exposed to pre-authentication remote code execution with no plugin or configuration prerequisites; immediate patching or verification via wp2shell.com is critical.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

Researchers disclosed two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, that can be chained to obtain pre-authentication remote code execution on versions 6.9.x through 7.0.1. Security firms observed active exploitation shortly after the July 17, 2026 disclosure, and patches are included in WordPress 7.0.2 and 6.9.5 with forced automatic updates enabled.

Why it matters: Administrators of WordPress sites running versions 6.9.x through 7.0.1 face unauthenticated remote code execution unless they upgrade to 7.0.2 or 6.9.5 or verify patch status.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

Researchers disclosed two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, that can be chained to obtain pre-authentication remote code execution on versions 6.9.x through 7.0.1. Security firms observed active exploitation shortly after the July 17, 2026 disclosure, and patches are included in WordPress 7.0.2 and 6.9.5 with forced automatic updates enabled.

Why it matters: Administrators of WordPress sites running versions 6.9.x through 7.0.1 face unauthenticated remote code execution unless they upgrade to 7.0.2 or 6.9.5 or verify patch status.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary