#wp2shell

12 posts · Last used 5d

Back to Timeline
The New Oil @thenewoil@mastodon.thenewoil.org · 5d ago
1
0
1
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 5d ago
wp2shell, a WordPress Core RCE chain (CVE-2026-63030, CVE-2026-60137), is exploited in the wild. Public PoC code is out. Patch WordPress now. #wp2shell #WordPress #RCE #CVE202663030 #CVE202660137 #InfoSec #WebSecurity #PatchNow https://securityonline.info/wp2shell-wordpress-core-rce/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
AmmarSpaces @AmmarSpaces@infosec.exchange · 6d ago
So, more explanation of wp2shell recently just popped out. The vulnerability were found by GPT 5.6 Sol. By using modified prompt from how it found the solution of Cycle Double Cover conjecture. It was initially found a SQL Injection, but after asked again if it can be elevated to RCE, it confirms it in 4 hours. Technical explanation on the vulnearbility also can be found in this writeup, have a good read fellas. https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/ #cybersecurity #infosec #security #wordpress #chatgpt #gptsol #wp2shell #airesearch #llm #vulnerability #vulnerabilityresearch
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 6d ago
The wp2shell chain turns two WordPress core bugs into unauthenticated RCE on default installs. Update to 6.9.5, 7.0.2, or 6.8.6 immediately. #WordPress #wp2shell #RCE #SQLInjection #RESTAPI #CVE https://securityexpress.info/wp2shell-wordpress-rce/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Matt Organ @Slater450413@infosec.exchange · Jul 19, 2026
Replying to @wdormann@infosec.exchange
@wdormann@infosec.exchange Just had a quick squiz at some servers I run with WordPress on based on the URLs mentioned in the article egrep -ir "rest_route=/batch/v1|wp/v2/categories|wp/v2/users" /var/log/apache2/* 21 requests starting 18/07/2026 05:30 UTC None of the requests have anything in common. Seems mostly like people poking around rather than spraying at this stage. #WordPress #CVE-2026-63030 #CVE-2026-60137  #wp2shell
0
1
0
thecybersecguru @thecybersecguru@infosec.exchange · Jul 18, 2026
🚨 CRITICAL: WordPress Core "wp2shell" RCE A single anonymous HTTP request can lead to Remote Code Execution on vulnerable WordPress Core installations. ⚠️ No plugins. ⚠️ No themes. ⚠️ No authentication required. Tracked as: 🔴 CVE-2026-63030 (REST API Batch Route Confusion → RCE) 🔴 CVE-2026-60137 (Facilitated SQL Injection) Affected versions • WordPress 6.9.0–6.9.4 • WordPress 7.0.0–7.0.1 ✅ Update immediately to WordPress 6.9.5 or 7.0.2. Due to the severity, WordPress has enabled forced automatic security updates for affected installations. 🔗 Full technical analysis: https://thecybersecguru.com/news/wordpress-core-rce-wp2shell/ #WordPress #WordPressSecurity #wp2shell #CVE202663030 #CVE202660137 #RCE #RemoteCodeExecution #SQLInjection #RESTAPI #CyberSecurity #InfoSec #WebSecurity #WebsiteSecurity #PatchNow #ThreatIntelligence #BlueTeam #SOC #Linux #PHP #ZeroDay #SecurityResearch #SysAdmin #DevSecOps
34
1
55
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 18, 2026
A critical WordPress wp2shell vulnerability allows remote code execution without a login. Learn how to scan your site and apply the urgent 7.0.2 update. #WordPress #wp2shell #CyberSecurity #Malware https://meterpreter.org/wordpress-wp2shell-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 18, 2026
Cloudflare deploys emergency WAF rules to block the critical WordPress wp2shell vulnerability. Update your site now to prevent severe RCE security risks. #WordPress #Cloudflare #wp2shell #CyberSecurity #WAF https://securityonline.info/wordpress-wp2shell-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
tomcat @tomcat@infosec.exchange · Jul 18, 2026

⚡ UPDATE: #wp2shell now has two CVEs, and a working proof-of-concept is public.

CVE-2026-63030 breaks REST batch routing CVE-2026-60137 injects SQL

Chained, they give an anonymous attacker code execution on affected WordPress sites.

How the exploit path works: https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html

1
0
0
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 18, 2026
#Wordpress: Critical Remote Code Execution (#RCE) chain of vulnerabilities CVE-2026-63030 and #SQLi SQL Injection CVE-2026-60137 dubbed #wp2shell in WordPress Core threaten 500+ million of websites. Patch now!: 👇 https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
0
0
0
Caitlin Condon @catc0n@infosec.exchange · Jul 18, 2026
Heyoo, there's a #wp2shell WordPress core RCE situation going on. The @vulncheck@infosec.exchange research team sussed out what we could determine from patches and public info, and so far, while it ain't *good*, it could maaaybe be worse. I guess we'll see come Sunday/Monday what details and exploitation status looks like, but it feels like we're gonna see attacks start basically now. https://www.vulncheck.com/blog/wp2shell
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 18, 2026
WordPress pre-auth RCE CVE-2026-63030 chains a REST batch bug with SQL injection. Details and a public PoC are out. Update to WordPress 7.0.2 now. #WordPress #PreAuthRCE #CVE202663030 #SQLInjection #wp2shell #WebSecurity #InfoSec https://securityonline.info/wordpress-pre-auth-rce-cve-2026-63030/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0

You've seen all posts