Elektrine lite

← Feed

@ifin@infosec.exchange

Post #3910866

2026-07-18 12:56 UTC

Apparently (?) there's a Pre-Auth RCE (!) in core WordPress (?!), but there are extremely few details as yet. If it's as gnarly as it sounds, a lot of sites are going to have a very bad time. We'll keep this story updated as details emerge. https://discourse.ifin.network/t/wp2shell-pre-auth-rce-in-wordpress-no-cve/672

Replies (2)

  • @ifin@infosec.exchange 2026-07-18 13:24

    This now has a CVE: CVE-2026-63030

    Open ##3911463

  • @tdelmas@mamot.fr 2026-07-18 13:04

    @ifin@infosec.exchange Well, it looks like a beautiful SQL injection. https://github.com/WordPress/wordpress-develop/compare/7.0.1...7.0.2#diff-1d050668621cbc3028e027d15e68438f4d879dd6e80ba98f9c9f69b9fb5469d0

    Open ##3916346