← Back to Feed

wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

CVE-2026-63030CVE-2026-60137

July 20, 2026 · Tenable Blog · Severity: HIGH

An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations.

Key Takeaways

  • An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations.
  • Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public.
☕ Buy a Coffee