← Back to Feed
wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
CVE-2026-63030CVE-2026-60137
July 20, 2026 · Tenable Blog · Severity: HIGH
An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations.
Key Takeaways
- An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations.
- Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public.