Forum Discussion
wp2shell (CVE-2026-63030, CVE-2026-60137): FAQs about exploit chain in WordPress Core
On July 17, 2026, WordPress released security updates addressing the wp2shell vulnerabilities alongside two GitHub Security Advisories. Adam Kues of Searchlight Cyber, who discovered and disclosed CVE-2026-63030, published research on the same day and chose to hold back the technical specifics given the severity of the finding. Searchlight Cyber also launched wp2shell.com, a testing tool that allows administrators to check whether their WordPress installation is vulnerable.
On July 20, Searchlight Cyber published a full technical breakdown of the attack chain.
wp2shell is a two-vulnerability exploit chain affecting WordPress Core.
|
CVE |
Description |
CVSSv3 |
|---|---|---|
|
WordPress Core REST API Batch-Route Confusion Remote Code Execution Vulnerability |
9.8 | |
|
WordPress Core WP_Query author__not_in SQL Injection Vulnerability |
5.9 |
Hexastrike began observing exploitation attempts in honeypots over the weekend following the July 17 disclosure and has since assisted with incident response in several confirmed attacks. Patchstack has also confirmed in-the-wild exploitation. Other researchers have reported seeing active exploitation in the wild.
For more information about the vulnerability, including the availability of patches and Tenable product coverage, please visit our blog.