← Back to Feed

wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

CVE-2026-63030CVE-2026-60137

July 20, 2026 · Tenable Blog · Severity: HIGH

This article answers frequently asked questions about the wp2shell exploit chain affecting WordPress Core. Two vulnerabilities, CVE-2026-63030 and CVE-2026-60137, allow unauthenticated attackers to achieve remote code execution. Patches have been released and forced automatic updates are enabled.

Key Takeaways

  • Two WordPress Core vulnerabilities can be chained for pre-authentication remote code execution.
  • Active exploitation and public proof-of-concept exploits appeared within hours of disclosure.
  • Patches are available in WordPress 7.0.2 and 6.9.5 with forced automatic updates.
☕ Buy a Coffee