As cited
Copy frozen at (site build).
vulnerabilities
wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution
On July 17, 2026, Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution chain affecting WordPress Core versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 through a route confusion flaw in the REST batch endpoint. Proof-of-concept tools circulated within hours, with attackers either escalating through SQL injection to upload malicious plugins or dropping webshells directly to disk, resulting in command execution via the web process. Defenders observe PHP and web server runtimes spawning shells, plugin directories appearing under wp-content/plugins/, and consistent post-exploitation discovery activity across vulnerable hosts.
Why it matters: Organizations running internet-facing WordPress instances on versions 6.9.0 to 6.9.4 or 7.0.0 to 7.0.1 face immediate pre-authentication compromise risk; patch to 6.9.5 or 7.0.2 immediately and treat any vulnerable instance as potentially compromised until patched, then hunt for shell spawning and suspicious plugin directories using provided IOCs.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution
Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution vulnerability chain in WordPress Core (CVE-2026-63030, CVE-2026-60137) affecting versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. The exploit leverages route confusion in the REST batch endpoint to execute SQL injection and ultimately achieve command execution on the server. Public proof-of-concept tools appeared within hours, and active scanning and exploitation attempts are already visible in telemetry across customer environments.
Why it matters: WordPress site operators with internet-facing instances on vulnerable versions (6.9.0-6.9.4 or 7.0.0-7.0.1) must patch immediately to 6.9.5 or 7.0.2; security teams should hunt for signs of post-exploitation activity (shell spawning, plugin directories under wp-content/plugins, web server processes initiating commands) while public tooling remains unmodified.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution
Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution vulnerability chain in WordPress Core (CVE-2026-63030, CVE-2026-60137) affecting versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. The exploit leverages route confusion in the REST batch endpoint to execute SQL injection and ultimately achieve command execution on the server. Public proof-of-concept tools appeared within hours, and active scanning and exploitation attempts are already visible in telemetry across customer environments.
Why it matters: WordPress site operators with internet-facing instances on vulnerable versions (6.9.0-6.9.4 or 7.0.0-7.0.1) must patch immediately to 6.9.5 or 7.0.2; security teams should hunt for signs of post-exploitation activity (shell spawning, plugin directories under wp-content/plugins, web server processes initiating commands) while public tooling remains unmodified.
- Source published
- First seen by Cybersecurity Tracker