An exploit has been revealed for a crucial ‘wp2shell’ distant code execution vulnerability affecting WordPress Core, making it crucial for admins to patch their websites instantly.
The wp2shell assault consists of two flaws, tracked as CVE-2026-63030 and CVE-2026-60137, that may be chained collectively to allow pre-authentication distant code execution in opposition to WordPress installations operating variations 6.9.x and seven.0.x.
The flaw was found by Searchlight Cyber’s Adam Kues, who says it may very well be exploited by an unauthenticated attacker in opposition to a default WordPress set up.
“Searchlight Cyber’s safety analysis workforce has found a pre-authentication RCE in WordPress core,” Searchlight Cyber defined.
“This assault has no conditions and might be exploited by nameless customers who’ve a typical set up of WordPress with none plugins.”
Searchlight Cyber estimates that over 500 million web sites use WordPress, making this vulnerability doubtlessly vital, particularly now {that a} publicly out there proof-of-concept exploit has been launched.
Because of the severity of the vulnerability, the WordPress Safety Crew has enabled necessary automated safety updates for supported installations operating affected variations and urged web site house owners to replace to WordPress 7.0.2 or 6.9.5 instantly.
“This can be a safety launch and we advocate that you simply replace your web site instantly,” WordPress mentioned in a safety announcement.
“Because of the severity of the problem, the WordPress.org workforce has enabled a pressured replace by way of the automated replace system for websites operating the affected variations.”
This concern isn’t a single vulnerability, however two separate flaws that may be mixed into an unauthenticated distant code execution chain.
The primary flaw, CVE-2026-63030, is a REST API batch route confusion vulnerability launched in WordPress 6.9. In accordance with an advisory on GitHub, this flaw might be mixed with an SQL injection concern to doubtlessly result in distant code execution.
The second vulnerability, CVE-2026-60137, is an SQL injection flaw in “.author__not_in‘ parameters ofWP_Query'. WordPress describes this as a high-severity SQL injection vulnerability affecting WordPress 6.8 and later.
In accordance with the WordPress advisory, the whole RCE chain impacts WordPress 6.9.0 – 6.9.4 and WordPress 7.0.0 – 7.0.1.
The SQL injection vulnerability additionally impacts WordPress 6.8.0 to six.8.5, however can’t be chained to distant code execution as a result of the REST API batch route confusion bug was added in WordPress 6.9.
The entire wp2shell assault chain has been fastened in WordPress 6.9.5 and seven.0.2.
Searchlight Cyber is at the moment withholding technical particulars to provide directors time to patch, however as a substitute has created a wp2shell.com web site the place directors can check their WordPress installations for vulnerabilities.
For organizations that can’t replace instantly, Searchlight Cyber recommends the next:
- Set up a plugin that fully blocks nameless entry to the REST API. or
- blocking
/wp-json/batch/v1and?rest_route=/batch/v1On the WAF degree.
The corporate warns that these mitigations ought to solely be used as a short lived measure till the system is up to date.
Cloudflare additionally introduced that it has launched net utility firewall (WAF) safety in opposition to each vulnerabilities throughout all plans, together with free accounts proxied behind the platform.
In accordance with Cloudflare, the rule block makes an attempt to use each a SQL injection flaw (CVE-2026-60137) and a REST API batch route confusion vulnerability (CVE-2026-63030).
“WAF safety reduces threat when prospects replace, however isn’t an alternative to patching,” Cloudflare mentioned.
Public PoC exploit launched
Searchlight Cyber delayed the discharge of technical particulars to provide directors time to use patches, however a number of proof-of-concept exploits have since been revealed on GitHub.
Some publicly out there exploits mix the 2 vulnerabilities to extract WordPress password hashes by way of SQL injection, crack administrator passwords to log in, and add malicious plugins to execute instructions.
Nevertheless, different proof-of-concept exploits declare to allow pre-authenticated distant code execution with out requiring administrator credentials, which is extra in step with the outline of the Searchlight Cyber flaw.
BleepingComputer contacted Searchlight Cyber and confirmed that their assault chain doesn’t require an administrator password.
Safety agency watchTowr mentioned after the exploit was made public that it had already seen the exploit within the wild.
“WordPress has a foul popularity on the subject of safety, however the actuality is that extremely impactful unauthenticated SQL injection and distant code execution vulnerabilities in WordPress core are literally fairly uncommon,” watchTowr CEO Benjamin Harris instructed BleepingComputer in an electronic mail.
“That’s what makes this totally different, and why everyone seems to be scrambling to patch it earlier than a widespread exploit takes maintain. The watchTowr workforce has already seen proof-of-concept exploits within the wild, and we’re beginning to see the primary indicators of real-world exploits.”
Given the provision of a publicly out there proof-of-concept exploit and the primary reported indications of an exploit within the wild, admins ought to replace their websites to WordPress 7.0.2 or 6.9.5 as quickly as attainable.

Safety groups doc 54% of profitable assaults and concern a warning on solely 14%. The remaining strikes invisibly via the surroundings.
Picus’ whitepaper reveals methods to check your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
