
Public PoCs Push Urgent Patch for WordPress wp2shell RCE
Public proof-of-concept exploits have surfaced for two chained WordPress Core flaws (CVE-2026-63030 and CVE-2026-60137) enabling unauthenticated remote code execution on WordPress 6.9.x and 7.0.x. WordPress released fixes in 6.9.5 and 7.0.2 with forced auto-updates; admins should patch immediately. Mitigations include blocking anonymous REST API access or specific endpoints, and Cloudflare has WAF protections. Tools like wp2shell.com let admins test vulnerability.
