21/07/2026
Public proof-of-concept exploits are now available for the critical "wp2shell" vulnerabilities affecting WordPress Core, significantly increasing the risk to unpatched websites.
The attack chain combines two security flaws, CVE-2026-63030 and CVE-2026-60137, allowing attackers to achieve pre-authentication remote code ex*****on (RCE) on WordPress sites running versions 6.9.x and 7.0.x.
Because these vulnerabilities are considered critical, the WordPress security team has activated automatic security updates for supported installations where possible. Website owners and administrators are strongly advised to update without delay to WordPress 7.0.2 or 6.9.5 to protect their sites from potential compromise.