Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details

A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed “wp2shell” has been disclosed in WordPress Core, putting an estimated 500 million-plus websites at risk of full takeover by completely unauthenticated attackers. The chain combines two separately tracked flaws CVE-2026-63030, a REST API batch-route confusion issue, and CVE-2026-60137, a SQL injection vulnerability in the author__not_in […]

The post Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: