THE article discusses two recently discovered WordPress vulnerabilities, known as WP2Shell, identified as CVE-2026-60137 and CVE-2026-63030. These vulnerabilities affect versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 of WordPress, allowing for unauthenticated remote code execution. Attackers can exploit these flaws to gain control of WordPress sites without any preconditions. WordPress has released patches, and Cloudflare has implemented rules to detect exploitation. Confirmed active exploits have been reported by various cybersecurity firms, raising concerns for the security of millions of WordPress sites globally.
WordPress flaws CVE-2026-60137 and CVE-2026-63030 allow RCE
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
WordPress wp2shell flaw lets attackers run code before login
elastic.co
-
Critical Vitest flaw exposes local files via browser mode bypass
securityonline.info
-
WordPress wp2shell exploit fuels surge in site scans and attacks
thehackernews.com
-
Critical WordPress Bug Lets Attackers Run Code Remotely
securityonline.info
-
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
darkreading.com
-
WordPress core flaw CVE-2026-63030 lets attackers execute code
isc.sans.edu
-
AI crafted WordPress exploit chain triggers urgent CVE patches
infosecurity-magazine.com
-
WordPress flaws CVE-2026-60137 and CVE-2026-63030 allow RCE
www.securityweek.com
-
Public PoC exploits hit critical WordPress CVEs, urging patches
securityaffairs.com
-
WordPress SQLi bug allows remote code execution, update now
securityonline.info
-
WordPress REST API flaw lets attackers run code remotely
rapid7.com