#cve202663030

3 posts · Last used 5d

Back to Timeline
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 5d ago
wp2shell, a WordPress Core RCE chain (CVE-2026-63030, CVE-2026-60137), is exploited in the wild. Public PoC code is out. Patch WordPress now. #wp2shell #WordPress #RCE #CVE202663030 #CVE202660137 #InfoSec #WebSecurity #PatchNow https://securityonline.info/wp2shell-wordpress-core-rce/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
thecybersecguru @thecybersecguru@infosec.exchange · Jul 18, 2026
🚨 CRITICAL: WordPress Core "wp2shell" RCE A single anonymous HTTP request can lead to Remote Code Execution on vulnerable WordPress Core installations. ⚠️ No plugins. ⚠️ No themes. ⚠️ No authentication required. Tracked as: 🔴 CVE-2026-63030 (REST API Batch Route Confusion → RCE) 🔴 CVE-2026-60137 (Facilitated SQL Injection) Affected versions • WordPress 6.9.0–6.9.4 • WordPress 7.0.0–7.0.1 ✅ Update immediately to WordPress 6.9.5 or 7.0.2. Due to the severity, WordPress has enabled forced automatic security updates for affected installations. 🔗 Full technical analysis: https://thecybersecguru.com/news/wordpress-core-rce-wp2shell/ #WordPress #WordPressSecurity #wp2shell #CVE202663030 #CVE202660137 #RCE #RemoteCodeExecution #SQLInjection #RESTAPI #CyberSecurity #InfoSec #WebSecurity #WebsiteSecurity #PatchNow #ThreatIntelligence #BlueTeam #SOC #Linux #PHP #ZeroDay #SecurityResearch #SysAdmin #DevSecOps
34
1
55
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 18, 2026
WordPress pre-auth RCE CVE-2026-63030 chains a REST batch bug with SQL injection. Details and a public PoC are out. Update to WordPress 7.0.2 now. #WordPress #PreAuthRCE #CVE202663030 #SQLInjection #wp2shell #WebSecurity #InfoSec https://securityonline.info/wordpress-pre-auth-rce-cve-2026-63030/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0

You've seen all posts