What's Happening?
WordPress has issued an urgent call for site administrators to patch critical 'wp2shell' remote code execution vulnerabilities affecting WordPress Core. The vulnerabilities, tracked as CVE-2026-63030 and CVE-2026-60137, can be exploited to achieve pre-authentication
remote code execution on WordPress installations running versions 6.9.x and 7.0.x. Discovered by Adam Kues of Searchlight Cyber, these flaws allow unauthenticated attackers to execute arbitrary code on a default WordPress installation. Public proof-of-concept exploits have been released, increasing the urgency for immediate patching.
Why It's Important?
With over 500 million websites using WordPress, the potential impact of these vulnerabilities is massive. The ability for attackers to execute code without authentication poses a significant threat to website security, potentially leading to data breaches, defacement, or further malware distribution. The release of public exploits heightens the risk of widespread exploitation, making it imperative for site administrators to update their installations promptly to protect against potential attacks.
What's Next?
WordPress has enabled forced automatic security updates for affected versions, urging site owners to update to WordPress 7.0.2 or 6.9.5 immediately. For those unable to update immediately, temporary mitigations include blocking anonymous access to the REST API or specific endpoints at the WAF level. Organizations should prioritize patching and monitor for any signs of exploitation. As the situation develops, maintaining up-to-date security measures and monitoring for vulnerabilities will be crucial in safeguarding WordPress sites.













