CVE Tools
Back to feed
Exploited in the wild WordPress core rce WordPress web-app

Критическую проблему в WordPress уже применяют для установки веб-шеллов

Хакер (xakep.ru)·By Мария Нефёдова··2 min read
CVE Tools coverage

Hackers are actively exploiting a critical vulnerability chain in WordPress core, known as wp2shell, to install malicious plugins and web shells on compromised sites. The issue combines an SQL injection flaw (CVE-2026-60137) with a REST API endpoint bug (CVE-2026-63030), enabling unauthenticated attackers to execute arbitrary code. Vulnerable versions include WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. Patches were released in versions 6.8.6, 6.9.5, and 7.0.2, but attackers have already deployed proof-of-concept exploits and are scanning the internet for exposed installations. Security researchers report that attackers create admin accounts, read sensitive files like wp-config.php, and use obfuscated payloads to maintain access.