< Back to all clusters
[TECHNOLOGY] · Poland, Netherlands · 5 sources

WordPress core flaw 'wp2shell' enables remote takeover, patches issued

A critical vulnerability in the WordPress core, dubbed “wp2shell” and tracked as CVE‑2026‑63030, allows an unauthenticated attacker to execute code remotely and take control of a site. The flaw was identified by Searchlight Cyber, and proof‑of‑concept exploit code has already been published. The National Cyber Security Centre (Netherlands) warned that exploitation is expected imminently, while CERT Polska issued an advisory about the same flaw combined with CVE‑2026‑60137, which together can lead to remote code execution without a user account. WordPress responded with forced automatic updates and released patched versions 6.8.6, 6.9.5 and 7.0.2. Over 41 % of all websites run WordPress, giving the issue a massive attack surface. Administrators are urged to apply the updates immediately to prevent takeover and data theft.