Kryptovaluta-ticker:
sysadmin fra Cyber Security News

Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details

Guru Baran
22 hours ago
6 Visninger
0 Kommentarer
Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details

Overview A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed “wp2shell” has been disclosed in WordPress Core, putting an estimated 500 million-plus websites at risk of full takeover by completely unauthenticated attackers. The chain combines two separately tracked flaws CVE-2026-63030, a REST API batch-route confusion issue, and CVE-2026-60137, a SQL injection vulnerability in the author__not_in parameter of WP_Query to achieve full server compromise on a stock WordPress installation with zero plugins installed. WordPress powers roughly 43 percent of all websites globally, making this one of the most consequential CMS security disclosures in recent memory. What sets wp2shell...

Læs hele artiklen hos kilden.

Deltag i diskussionen — kommenter, stem og del links.

Registrer
Var dette nyttigt?
Del:

Kommentarer (0)

Log venligst ind eller opret dig for at deltage i diskussionen

Ingen kommentarer ennå. Bli den første til å kommentere!