A newly disclosed a pre-authentication distant code execution (RCE) vulnerability in WordPress Core, dubbed “wp2shell,” that requires no authentication and impacts inventory WordPress installations with zero plugins put in. Provided that WordPress powers an estimated 500 million web sites globally.
The flaw represents one of the crucial vital CMS safety disclosures in current reminiscence. The problem stems from a REST API batch-route confusion mixed with a SQL injection flaw that collectively allow full RCE.
Crucial WordPress Core Flaw
Researcher Adam Kues of Assetnote recognized and reported the vulnerability, which has now been assigned CVE-2026-63030 (GHSA-ff9f-jf42-662q). A second, associated SQL injection concern reported by TF1T, dtro, and haongo was assigned CVE-2026-60137 (GHSA-fpp7-x2x2-2mjf).
As a result of exploitation requires no preconditions and no legitimate credentials, any nameless attacker can compromise a weak website out of the field.
Searchlight Cyber has withheld technical exploitation particulars to present website homeowners time to patch, however has launched a public scanner at wp2shell[.]com so directors can verify publicity with no need deep technical experience.
Affected Variations
- WordPress ≤6.8.5: not affected by the RCE chain (6.8.x affected solely by CVE-2026-60137).
- WordPress 6.9.0–6.9.4: affected by each vulnerabilities.
- WordPress 7.0.0–7.0.1: affected by each vulnerabilities.
- WordPress 7.1 beta releases: affected; mounted in 7.1 beta2.
Patches and Mitigation
The WordPress safety crew responded with model 7.0.2, addressing one crucial and one high-severity concern. Backport releases embrace 6.9.5 and 6.8.6.
Because of the severity of the RCE, WordPress has enabled pressured auto-updates for websites operating affected variations, although directors are urged to confirm updates manually.
Web site homeowners can replace by way of the WordPress Dashboard beneath Updates → Replace Now, or obtain the discharge straight from WordPress.org.
For environments the place speedy patching isn’t possible, Searchlight Cyber recommends non permanent mitigations:
- Set up a plugin that blocks nameless entry to the REST API fully
- Block
/wp-json/batch/v1and?rest_route=/batch/v1on the WAF degree
These measures might disrupt reliable REST API performance and ought to be handled strictly as emergency stopgaps till a full replace might be utilized.
Mixed with WordPress’s huge put in base, wp2shell has the potential for widespread automated exploitation as soon as technical particulars change into public or are reverse-engineered from patch diffs.
Safety groups and website directors are strongly suggested to replace instantly, confirm patch standing utilizing the wp2shell[.]com software, and monitor logs for suspicious REST API batch requests focusing on /wp-json/batch/v1.
Strengthen Your SOC by Accelerating Menace Detection & Speedy Investigations. -> Combine ANY.RUN With Your SOC Now.









