Post #3910866
2026-07-18 12:56 UTC
Apparently (?) there's a Pre-Auth RCE (!) in core WordPress (?!), but there are extremely few details as yet.
If it's as gnarly as it sounds, a lot of sites are going to have a very bad time. We'll keep this story updated as details emerge.
https://discourse.ifin.network/t/wp2shell-pre-auth-rce-in-wordpress-no-cve/672
Replies (2)
-
@ifin@infosec.exchange 2026-07-18 13:24
This now has a CVE: CVE-2026-63030
-
@tdelmas@mamot.fr 2026-07-18 13:04
@ifin@infosec.exchange Well, it looks like a beautiful SQL injection. https://github.com/WordPress/wordpress-develop/compare/7.0.1...7.0.2#diff-1d050668621cbc3028e027d15e68438f4d879dd6e80ba98f9c9f69b9fb5469d0