Overview A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed “wp2shell” has been disclosed in WordPress Core, putting an estimated 500 million-plus websites at risk of full takeover by completely unauthenticated attackers. The chain combines two separately tracked flaws CVE-2026-63030, a REST API batch-route confusion issue, and CVE-2026-60137, a SQL injection vulnerability in the author__not_in parameter of WP_Query to achieve full server compromise on a stock WordPress installation with zero plugins installed. WordPress powers roughly 43 percent of all websites globally, making this one of the most consequential CMS security disclosures in recent memory. What sets wp2shell...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!