CVE Tools
Back to feed
PoC public WordPress Core rce WordPress web-app

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

BleepingComputer·By Lawrence Abrams··4 min read
CVE Tools coverage

Public proof-of-concept exploits have emerged for the critical 'wp2shell' remote code execution vulnerabilities in WordPress Core, urging immediate action from site administrators. The vulnerabilities, CVE-2026-63030 and CVE-2026-60137, allow unauthenticated attackers to execute arbitrary code on affected installations running versions 6.9.x and 7.0.x. These flaws can be exploited without prior authentication and affect default setups with no additional plugins required. The WordPress security team has activated forced auto-updates to address the issue, recommending users upgrade to version 7.0.2 or 6.9.5 as soon as possible.