Exploited in the wild WordPress core rce WordPress web-app
Критическую проблему в WordPress уже применяют для установки веб-шеллов
CVE Tools coverage
Hackers are actively exploiting a critical vulnerability chain in WordPress core, known as wp2shell, to install malicious plugins and web shells on compromised sites. The issue combines an SQL injection flaw (CVE-2026-60137) with a REST API endpoint bug (CVE-2026-63030), enabling unauthenticated attackers to execute arbitrary code. Vulnerable versions include WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. Patches were released in versions 6.8.6, 6.9.5, and 7.0.2, but attackers have already deployed proof-of-concept exploits and are scanning the internet for exposed installations. Security researchers report that attackers create admin accounts, read sensitive files like wp-config.php, and use obfuscated payloads to maintain access.