Critical WordPress wp2shell vulnerability enables pre-authentication remote code execution
Security researchers have identified 'wp2shell' (CVE-2026-63030 and CVE-2026-60137), a set of critical vulnerabilities in WordPress Core versions 6.9 through 7.0.1. The flaw involves a REST API batch request desynchronization issue that, when chained with SQL injection, allows for remote code execution on affected servers.
Key Takeaways
- Vulnerability chain affects WordPress Core versions 6.9.0–6.9.4 and 7.0.0–7.0.1
- Exploit leverages two CVEs: CVE-2026-63030 (REST API) and CVE-2026-60137 (SQLi)
- Attackers can obtain admin credentials via SQL injection before uploading malicious plugins
- Patched versions 6.9.5 and 7.0.2 were released on July 17, 2026, to neutralize the chain
- A scanner tool from researcher ZephrFish helps identifying vulnerable 6.9 and 7.0 instances
Why It Matters
The wp2shell vulnerability represents a severe threat to video streaming infrastructures that use WordPress for CMS or front-end management. Because the exploit targets core code and requires no authentication or specific plugins, the attack surface is vast and difficult to defend without immediate patching. For engineers, the immediate implication is a complete loss of server integrity if the /batch/v1 endpoint remains exposed. Within the streaming ecosystem, where WordPress often powers high-traffic content portals or community hubs, this flaw presents a ready-made entry point for botnets or data exfiltration. Operators should monitor for unusual POST requests to the REST API batch endpoint while confirming that forced updates to version 7.0.2 have successfully completed.
Additional Context
The disclosure of wp2shell on July 17, 2026, triggered an immediate response from the WordPress Security Team, which initiated forced automatic updates for millions of sites. According to reporting from The Hacker News on July 17, 2026, the vulnerability is particularly dangerous because it functions on stock installs, bypassing the typical defense-in-depth provided by a lack of third-party plugins. While WordPress's inherent auto-update system provides a safety net, analysts at security firm Hadrian noted on July 18, 2026, that these updates can frequently stall due to server-side file permission issues or disk space constraints, necessitating manual verification by site administrators. External intelligence suggests that the threat landscape transitioned from theoretical to active within hours of the patch release. Per VulnCheck on July 18, 2026, early indicators of exploitation were reported by PatchStack as early as late Friday evening, shortly after technical details began circulating in the research community. This rapid turnaround is consistent with historical patterns observed by the WP-SHELLSTORM threat group, which typically targets public core vulnerabilities to deploy web shells for mass compromise. Sites behind persistent object caches like Redis or Memcached may have a partial mitigation against the specific REST API desynchronization path, according to Rapid7, but these do not address the secondary SQL injection vector. Industry response has shifted toward a "patch and verify" posture. Wordfence reported on July 18, 2026, that it had deployed specialized firewall rules for its premium customers to block the specific 'author__not_in' parameter manipulation used in the SQL injection phase of the chain. However, Cloudflare cautioned on July 17, 2026, that WAF rules should be viewed as temporary measures, as attackers can frequently mutate the REST API payload to evade signature-based detection. These developments underscore a growing trend in 2026 of high-impact core CMS vulnerabilities that require centralized emergency intervention to maintain web infrastructure stability.
Read full article at blog.zsec.uk
Get this in your inbox → Subscribe
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source