CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3046

As cited

Copy frozen at (site build).

vulnerabilities

wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution

On July 17, 2026, Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution chain affecting WordPress Core versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 through a route confusion flaw in the REST batch endpoint. Proof-of-concept tools circulated within hours, with attackers either escalating through SQL injection to upload malicious plugins or dropping webshells directly to disk, resulting in command execution via the web process. Defenders observe PHP and web server runtimes spawning shells, plugin directories appearing under wp-content/plugins/, and consistent post-exploitation discovery activity across vulnerable hosts.

Why it matters: Organizations running internet-facing WordPress instances on versions 6.9.0 to 6.9.4 or 7.0.0 to 7.0.1 face immediate pre-authentication compromise risk; patch to 6.9.5 or 7.0.2 immediately and treat any vulnerable instance as potentially compromised until patched, then hunt for shell spawning and suspicious plugin directories using provided IOCs.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution

Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution vulnerability chain in WordPress Core (CVE-2026-63030, CVE-2026-60137) affecting versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. The exploit leverages route confusion in the REST batch endpoint to execute SQL injection and ultimately achieve command execution on the server. Public proof-of-concept tools appeared within hours, and active scanning and exploitation attempts are already visible in telemetry across customer environments.

Why it matters: WordPress site operators with internet-facing instances on vulnerable versions (6.9.0-6.9.4 or 7.0.0-7.0.1) must patch immediately to 6.9.5 or 7.0.2; security teams should hunt for signs of post-exploitation activity (shell spawning, plugin directories under wp-content/plugins, web server processes initiating commands) while public tooling remains unmodified.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution

Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution vulnerability chain in WordPress Core (CVE-2026-63030, CVE-2026-60137) affecting versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. The exploit leverages route confusion in the REST batch endpoint to execute SQL injection and ultimately achieve command execution on the server. Public proof-of-concept tools appeared within hours, and active scanning and exploitation attempts are already visible in telemetry across customer environments.

Why it matters: WordPress site operators with internet-facing instances on vulnerable versions (6.9.0-6.9.4 or 7.0.0-7.0.1) must patch immediately to 6.9.5 or 7.0.2; security teams should hunt for signs of post-exploitation activity (shell spawning, plugin directories under wp-content/plugins, web server processes initiating commands) while public tooling remains unmodified.

VendorsGitHubWordPressElastic
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary