THE article discusses two recently discovered WordPress vulnerabilities, known as WP2Shell, identified as CVE-2026-60137 and CVE-2026-63030. These vulnerabilities affect versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 of WordPress, allowing for unauthenticated remote code execution. Attackers can exploit these flaws to gain control of WordPress sites without any preconditions. WordPress has released patches, and Cloudflare has implemented rules to detect exploitation. Confirmed active exploits have been reported by various cybersecurity firms, raising concerns for the security of millions of WordPress sites globally.
WordPress flaws CVE-2026-60137 and CVE-2026-63030 allow RCE
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
cybersixt.com
-
WordPress core flaw CVE-2026-63030 lets attackers execute code
cybersixt.com
-
AI crafted WordPress exploit chain triggers urgent CVE patches
cybersixt.com
-
WordPress flaws CVE-2026-60137 and CVE-2026-63030 allow RCE
www.securityweek.com
-
Public PoC exploits hit critical WordPress CVEs, urging patches
cybersixt.com
-
WordPress SQLi bug allows remote code execution, update now
cybersixt.com
-
WordPress REST API flaw lets attackers run code remotely
cybersixt.com
-
WordPress wp2shell Flaw Lets Attackers Run Code Remotely
cybersixt.com
-
Cloudflare Deploys WAF Rules to Block WordPress RCE and SQLi
cybersixt.com