Key Takeaways
- A critical WordPress core vulnerability chain could enable unauthenticated remote code execution.
- Public proof-of-concept exploit code is available.
- No plugins, credentials, or user interaction are required for exploitation.
- Organizations should apply vendor-recommended updates immediately.
- Temporary mitigations should only be used until patches can be deployed.
Beyond addressing the immediate vulnerability, organizations should evaluate whether their broader cybersecurity programs, incident response processes, and vulnerability management practices are designed to address emerging threats.
Executive Summary
Security researchers have identified a critical WordPress core vulnerability chain known as “wp2shell” that could affect more than 500 million websites. The vulnerability enables unauthenticated remote code execution (RCE) against default WordPress installations and requires no plugins, custom configurations, user interaction, or prior access to exploit.
Because public proof-of-concept (PoC) exploit code is available, organizations should prioritize patching affected systems immediately or implement temporary mitigation measures if patches cannot be deployed promptly.
Understanding the Vulnerability
The wp2shell attack chain consists of two vulnerabilities, CVE-2026-63030 and CVE-2026-60137. When chained together, these vulnerabilities enable a pre-authentication RCE attack against vulnerable WordPress core installations. An attacker does not require valid credentials, user interaction, plugins, or special site configurations to exploit the flaw.
The vulnerabilities function as follows:
- CVE-2026-63030 allows an attacker to bypass security controls that normally restrict access to sensitive WordPress functionality.
- CVE-2026-60137 is a SQL injection vulnerability that enables malicious manipulation of database queries.
While each vulnerability is serious on its own, chaining them together could allow an attacker to:
- Execute arbitrary code remotely
- Create unauthorized administrator accounts
- Install malicious plugins or web shells
- Modify website content and configurations
- Gain persistent access to the affected environment
Who Is Affected?
Organizations running affected versions of WordPress core, including default installations, may be vulnerable to the wp2shell attack chain. Because exploitation does not require authentication or additional plugins, organizations should prioritize remediation of internet-facing WordPress websites.
Immediate Actions to Protect Your Organization
Organizations should immediately update affected WordPress installations according to the table below:
| Current Version | Recommended Update |
|---|---|
| WordPress 7.0.0 - 7.0.1 | WordPress 7.0.2 |
| WordPress 6.9.0 - 6.9.4 | WordPress 6.9.5 |
| WordPress 7.1 Beta | WordPress 7.1 Beta 2 |
| WordPress 6.8.0 - 6.8.5* | WordPress 6.8.6 |
*Affected by CVE-2026-60137 but not the full wp2shell attack chain.
If immediate patching is not possible, organizations should consider implementing temporary mitigation measures, including:Â
- Restrict anonymous access to the WordPress REST API when operationally feasible.
- Block the following endpoints at the web application firewall (WAF) level:
/wp-json/batch/v1?rest_route=/batch/v1
Organizations should validate any temporary mitigations within their environments and apply vendor-recommended updates as soon as possible.
How ACA Can Help Strengthen Your Defense
ACA Aponix  helps organizations strengthen cybersecurity programs, improve operational resilience, and address evolving cyber risks. Our services include:
- Aponix Protect helps firms address evolving cyber threats through a flexible and scalable cybersecurity program. The solution is designed to strengthen security practices, improve cyber resilience, and support changing business needs.
- Aponix Penetration Testing identifies exploitable vulnerabilities before threat actors can leverage them and provides actionable recommendations to strengthen security controls.
- Aponix Incident Response Planning and Tabletop Exercises help organizations validate response procedures, clarify stakeholder roles and responsibilities, and improve preparedness for cybersecurity incidents.
Contact our experts to assess your exposure, strengthen your cybersecurity posture, and reduce the risk of exploitation from emerging threats.
Skip to content