Tag

Wp2shell

All articles tagged with #wp2shell

Public PoCs Push Urgent Patch for WordPress wp2shell RCE
technology15 hours ago

Public PoCs Push Urgent Patch for WordPress wp2shell RCE

Public proof-of-concept exploits have surfaced for two chained WordPress Core flaws (CVE-2026-63030 and CVE-2026-60137) enabling unauthenticated remote code execution on WordPress 6.9.x and 7.0.x. WordPress released fixes in 6.9.5 and 7.0.2 with forced auto-updates; admins should patch immediately. Mitigations include blocking anonymous REST API access or specific endpoints, and Cloudflare has WAF protections. Tools like wp2shell.com let admins test vulnerability.

Emergency Patch Rolled Out After wp2shell RCE Threat Targets WordPress
cyber-security18 hours ago

Emergency Patch Rolled Out After wp2shell RCE Threat Targets WordPress

A critical, pre-authentication remote code execution flaw named wp2shell in WordPress Core affects roughly 500 million+ sites. It stems from a REST API batch-route confusion that enables unauthenticated attackers to execute code on vulnerable WordPress installations. The issue affects WordPress core versions 6.9.0–6.9.4, 7.0.0–7.0.1 (and 7.1 beta); fixes have been shipped in WordPress 7.0.2 with backports to 6.8.6 and 6.9.5. WordPress is auto-updating affected sites, and admins should update immediately. If patching isn’t possible yet, block anonymous REST API access or the batch endpoints as temporary mitigations and use the wp2shell.com scanner to check exposure.