What's Happening?
WordPress has announced the release of public exploits for critical remote code execution vulnerabilities known as 'wp2shell', affecting WordPress Core. These vulnerabilities, identified as CVE-2026-63030 and CVE-2026-60137, can be exploited together
to achieve pre-authentication remote code execution on WordPress installations running versions 6.9.x and 7.0.x. The flaws were discovered by Searchlight Cyber, which highlighted the potential for unauthenticated attackers to exploit these vulnerabilities on default WordPress installations. With over 500 million websites using WordPress, the impact of these vulnerabilities is significant, prompting WordPress to enable forced automatic security updates for affected versions. Administrators are urged to update to WordPress 7.0.2 or 6.9.5 immediately to mitigate the risk.
Why It's Important?
The release of public proof-of-concept exploits for the 'wp2shell' vulnerabilities poses a substantial threat to the security of millions of websites globally. These vulnerabilities allow attackers to execute code remotely without authentication, potentially leading to unauthorized access and control over affected sites. The widespread use of WordPress amplifies the urgency for site administrators to apply patches promptly to prevent exploitation. The vulnerabilities could lead to data breaches, defacement, or other malicious activities, impacting businesses, individuals, and organizations relying on WordPress for their online presence. The situation underscores the importance of timely security updates and proactive measures in maintaining cybersecurity.
What's Next?
Administrators are advised to update their WordPress installations to the latest versions immediately to protect against these vulnerabilities. For those unable to update promptly, temporary measures such as blocking anonymous access to the REST API or specific routes at the WAF level are recommended. Cloudflare has deployed Web Application Firewall protections to mitigate exposure while updates are applied. As public exploits circulate, the risk of in-the-wild exploitation increases, making it crucial for administrators to act swiftly. Continued monitoring and collaboration with security firms will be essential to address any emerging threats related to these vulnerabilities.













