WP2Shell WordPress Exploit Technical Analysis and Real Attack Data
1. Executive summary The "wp2shell" exploit chain combines two vulnerabilities in WordPress Core — CVE-2026-60137 (CVSS 5.9 MEDIUM, SQL Injection) and CVE-
1. Executive summary The "wp2shell" exploit chain combines two vulnerabilities in WordPress Core — CVE-2026-60137 (CVSS 5.9 MEDIUM, SQL Injection) and CVE-
1. Executive summary WordPress Core is affected by a critical interpretation conflict vulnerability (CVE-2026-63030, CVSS 9.8 CRITICAL) in the REST API batch endpoint,
1. Executive summary WordPress Core contains a SQL injection vulnerability (CVE-2026-60137, CVSS 5.9 MEDIUM) in the author__not_in parameter of WP_Query,
1. Executive summary CVE-2026-63030 (CVSS 9.8 CRITICAL, CWE-436) is an unauthenticated remote code execution vulnerability in WordPress Core, exploited via the REST
1. Executive summary CVE-2026-63030 is a critical unauthenticated remote code execution (RCE) vulnerability in WordPress Core, exploitable via the WordPress REST API batch endpoint.