← Back to Feed
wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
CVE-2026-63030CVE-2026-60137
July 20, 2026 · Tenable Blog · Severity: HIGH
This article answers frequently asked questions about the wp2shell exploit chain affecting WordPress Core. Two vulnerabilities, CVE-2026-63030 and CVE-2026-60137, allow unauthenticated attackers to achieve remote code execution. Patches have been released and forced automatic updates are enabled.
Key Takeaways
- Two WordPress Core vulnerabilities can be chained for pre-authentication remote code execution.
- Active exploitation and public proof-of-concept exploits appeared within hours of disclosure.
- Patches are available in WordPress 7.0.2 and 6.9.5 with forced automatic updates.