< Back to all clusters
[TECHNOLOGY] · Germany · 2 sources

started · updated

WordPress core flaw WP2Shell enables remote server takeover

A critical WordPress core vulnerability, dubbed WP2Shell, was disclosed in July 2026. It combines two flaws – CVE‑2026‑60137 (an SQL‑injection in the author__not_in parameter) and CVE‑2026‑63030 (a REST‑API routing error) – to create a pre‑authentication remote code execution chain with a CVSS score of 9.8. The BSI‑Cyber‑Security warning (BITS‑H 2026‑271984) classifies the issue as orange, urging immediate mitigation.

WordPress released core updates on 17 July 2026 that patch both CVEs. The vulnerability affects core versions 6.8.x, 6.9.x, and 7.0.x, while older releases are not vulnerable. Security firm Wordfence reported over 11 million blocked attack attempts exploiting the chain, highlighting the scale of the threat. Agencies and operators of multiple WordPress sites are advised to verify that the updates are installed and to check for signs of compromise.

The flaws were discovered by Searchlight Cyber, partly with AI assistance, and have quickly appeared on exploit markets, underscoring the urgency for site owners worldwide to apply the patches.

Entities

Bundesamt für Sicherheit in der Informationstechnik (BSI) · Searchlight Cyber · WP2Shell · WordPress · Wordfence