Crypto Ticker:
sysadmin from Cyber Security News

Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details

Guru Baran
22 hours ago
5 Views
0 Comments
Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details

Overview A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed “wp2shell” has been disclosed in WordPress Core, putting an estimated 500 million-plus websites at risk of full takeover by completely unauthenticated attackers. The chain combines two separately tracked flaws CVE-2026-63030, a REST API batch-route confusion issue, and CVE-2026-60137, a SQL injection vulnerability in the author__not_in parameter of WP_Query to achieve full server compromise on a stock WordPress installation with zero plugins installed. WordPress powers roughly 43 percent of all websites globally, making this one of the most consequential CMS security disclosures in recent memory. What sets wp2shell...

Read the full article at the source.

Join the discussion — comment, vote, and submit links.

Register
Was this helpful?
Share:

Comments (0)

Please login or register to join the discussion

No comments yet. Be the first to comment!