As cited
Copy frozen at (site build).
vulnerabilities
wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve unauthenticated remote code execution on WordPress 6.9.x and 7.0.x installations. Active exploitation began within days of the July 17, 2026 disclosure, with public proof-of-concept code circulating and multiple security firms confirming attacks in the wild. Patches are available in WordPress 7.0.2 and 6.9.5, with WordPress.org enabling forced automatic updates for affected installations.
Why it matters: All WordPress administrators running versions 6.9.0 through 7.0.1 are exposed to pre-authentication remote code execution with no plugin or configuration prerequisites; immediate patching or verification via wp2shell.com is critical.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
No summary had been written when this copy was frozen.
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
Researchers disclosed two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, that can be chained to obtain pre-authentication remote code execution on versions 6.9.x through 7.0.1. Security firms observed active exploitation shortly after the July 17, 2026 disclosure, and patches are included in WordPress 7.0.2 and 6.9.5 with forced automatic updates enabled.
Why it matters: Administrators of WordPress sites running versions 6.9.x through 7.0.1 face unauthenticated remote code execution unless they upgrade to 7.0.2 or 6.9.5 or verify patch status.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
Researchers disclosed two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, that can be chained to obtain pre-authentication remote code execution on versions 6.9.x through 7.0.1. Security firms observed active exploitation shortly after the July 17, 2026 disclosure, and patches are included in WordPress 7.0.2 and 6.9.5 with forced automatic updates enabled.
Why it matters: Administrators of WordPress sites running versions 6.9.x through 7.0.1 face unauthenticated remote code execution unless they upgrade to 7.0.2 or 6.9.5 or verify patch status.
- Source published
- First seen by Cybersecurity Tracker