www.securityweek.com 7/20/2026, 5:50:59 AM · external

WordPress flaws CVE-2026-60137 and CVE-2026-63030 allow RCE

WordPress flaws CVE-2026-60137 and CVE-2026-63030 allow RCE
Developing story malware 9 articles tracked
WordPress core flaws CVE-2026-60137 and CVE-2026-63030 exploited in the wild
CyberSIXT Evidence Panel
Primary Source wordpress.org
CISA KEV Not in KEV
Patch Patch Status Unknown

THE article discusses two recently discovered WordPress vulnerabilities, known as WP2Shell, identified as CVE-2026-60137 and CVE-2026-63030. These vulnerabilities affect versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 of WordPress, allowing for unauthenticated remote code execution. Attackers can exploit these flaws to gain control of WordPress sites without any preconditions. WordPress has released patches, and Cloudflare has implemented rules to detect exploitation. Confirmed active exploits have been reported by various cybersecurity firms, raising concerns for the security of millions of WordPress sites globally.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline