WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating. Key takeaways: Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execution against WordPress 6.9.x and 7.0.x installations. Multiple security firms have confirmed in-the-wild exploitation, with public proof-of-concept exploits appearing within hours of the July 17, 2026 disclosure. Patches are available in WordPress 7.0.2 and 6.9.5; WordPress.org has enabled forced automatic updates across affected supported installations. Background Tenable's Research Special Operations (RSO) team has compiled this blog to answer Frequently Asked Questions (FAQ) regarding wp2shell, two vulnerabilities in WordPress Core that can be chained together to achieve pre-authentication remote code execution. FAQ What is wp2shell? wp2shell is the name given to two vulnerabilities in WordPress Core. When was wp2shell first disclosed? On July 17, 2026, WordPress released security updates addressing the wp2shell vulnerabilities alongside two GitHub Security Advisories. Adam Kues of Searchlight Cyber, who discovered and disclosed CVE-2026-63030, published research on the same day and chose to hold back the technical specifics given the severity of the finding. Searchlight Cyber also launched wp2shell.com , a testing tool that allows administrators to check whether their WordPress installation is vulnerable. On July 20, Searchlight Cyber published a full technical breakdown of the attack chain. What are the vulnerabilities associated with wp2shell? wp2shell is a two-vulnerability exploit chain affecting WordPress Core. CVE Description CVSSv3 CVE-2026-63030 WordPress Core REST API Batch-Route Confusion Remote Code Execution Vulnerability 9.8 CVE-2026-60137 WordPress Core WP_Query author__not_in SQL Injection Vulnerability 5.9 CVE-2026-63030 is a REST API batch-route confusion weakness introduced in WordPress 6.9. CVE-2026-60137 is a SQL injection flaw in the author__not_in parameter of WP_Query , present in WordPress 6.8 and later. When chained on WordPress 6.9.0 through 7.0.1, the two flaws allow an unauthenticated attacker to reach the REST API batch endpoint at /wp-json/batch/v1 and achieve remote code execution. CVE-2026-60137 was discovered and disclosed by security researchers TF1T, dtro, and haongo. CVE-2026-60137 also affects WordPress 6.8.0 through 6.8.5 as a standalone SQL injection issue. Because CVE-2026-63030 was introduced in WordPress 6.9, the full RCE chain is only achievable on 6.9.x and 7.0.x installations. How severe is the wp2shell vulnerability chain? An anonymous, unauthenticated user can execute the chain against a default WordPress installation with no plugins required. No preconditions exist beyond the default WordPress configuration. Cloudflare notes that the vulnerable code path is reached when “a persistent object cache is not in use.” Note: wp2shell targets WordPress Core itself rather than a plugin or theme. All four prior WordPress-related entries in the CISA Known Exploited Vulnerabilities (KEV) catalog involve plugins, not core. Pre-authentication remote code execution in WordPress Core is uncommon. CVE Product Added to KEV Ransomware CVE-2026-41940 WebPros cPanel & WHM and WP2 (WordPress Squared) April 30, 2026 Known CVE-2020-25213 WordPress File Manager Plugin November 3, 2021 Unknown CVE-2020-11738 WordPress Snap Creek Duplicator Plugin November 3, 2021 Unknown CVE-2019-9978 WordPress Social Warfare Plugin November 3, 2021 Unknown How widespread are the attacks exploiting wp2shell? WordPress is the most widely deployed content management system in the world. Some hosted installations will receive patc…
AI Analysis
Technical Summary
The wp2shell exploit chain involves two WordPress Core vulnerabilities: CVE-2026-63030, a REST API batch-route confusion vulnerability introduced in WordPress 6.9, and CVE-2026-60137, a SQL injection vulnerability in the author__not_in parameter of WP_Query present since WordPress 6.8. When chained on WordPress versions 6.9.0 through 7.0.1, these allow an unauthenticated attacker to reach the /wp-json/batch/v1 REST API endpoint and achieve remote code execution. CVE-2026-60137 alone affects WordPress 6.8.0 through 6.8.5 as a standalone SQL injection. The exploit requires no plugins or special configuration beyond default WordPress setups without persistent object caching. Multiple security firms have confirmed in-the-wild exploitation, with public proof-of-concept exploits appearing within hours of disclosure. Patches are available in WordPress 6.8.6, 6.9.5, and 7.0.2, and forced automatic updates have been enabled for supported installations. Temporary mitigations include blocking REST API batch endpoint access via plugins or WAF rules. No public attribution or IoCs are currently available.
Potential Impact
An unauthenticated attacker can achieve remote code execution on affected WordPress installations, potentially allowing full system compromise. The exploit chain requires no authentication or plugins and affects default WordPress Core installations from versions 6.9.0 through 7.0.1. The SQL injection vulnerability alone affects versions 6.8.0 through 6.8.5. Active exploitation has been confirmed in the wild shortly after public disclosure, increasing the risk of compromise for unpatched systems.
Mitigation Recommendations
Official patches addressing these vulnerabilities were released on July 17, 2026, and WordPress.org has enabled forced automatic updates for supported affected versions. Users should immediately update to WordPress 6.8.6, 6.9.5, or 7.0.2 or later. For installations unable to update immediately, temporary mitigations include installing plugins that block unauthenticated access to the REST API batch endpoint, blocking /wp-json/batch/v1 and ?rest_route=/batch/v1 at the web application firewall level, or deploying a custom PHP plugin to restrict unauthenticated access to the batch endpoint. Cloudflare has also deployed WAF rules covering these vulnerabilities for proxied sites. These mitigations are interim and do not replace applying the official patches.
Indicators of Compromise
- cve: CVE-2026-63030
- cve: CVE-2026-60137
- hash: 12de8ce21bc534a968c327c00f2aa933b9034bc39b367ad1659f5aaa8be07744
- hash: 37d86716edcb5b481d5d34b38b3bb4b522fcabdf0baf9b0523a0a61957620fad
- hash: 4f4dc354dfa3ab9df33107b02106424d9940119363ceaff3399aefa8b14859dc
- hash: 5588eb0d473bbc104ecb7d41037a747280eba03956a3d4c11368e4f0bd427ead
- hash: 67ce5c125611078c2a6294faacd378b7dccbfb490641a0ca0822b071a22f759c
- hash: 9c1bf6681ca94ab703d4f393fbfdd0acfb081285cd47ea4cf718ff9b71835722
- hash: d3e34d9306106aca15b1deb6dcfbe169c5f0df470bd22095845d553a60cbfd1e
- hash: d4cf7b5d8722236de52e9bad855b4ed4d99f18a561d192aec33525ec89557a7c
- hash: d8dfdab3a4358dbcd0eb129494d9e64b8392ef564bdc4cbe73e238c6d3ba51cd
- hash: ee8395666b9367967749757da27784922fdc18dc3e85db864d30fa703eb9db18
- hash: 2a1410d8e2a8337ac2171cedea8c0fdc47c647a0
- hash: 58eca847e9eae9e6b08cc211f1559817b71bc4cc
- hash: d9a220c8039f1c4d72cae7ccb8b3a33dec8815be
- hash: e9756e2338f84746007235e4cab7a70d5b3ca47f
- hash: ebea44890f434d5d67ede22009a3f4bb5cac33f8
- ip: 172.235.128.52
- ip: 79.177.131.206
- ip: 94.100.52.128
WordPress Exploitation Underway (CVE-2026-63030), (Mon, Jul 20th)
Description
An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating. Key takeaways: Two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to achieve pre-authentication remote code execution against WordPress 6.9.x and 7.0.x installations. Multiple security firms have confirmed in-the-wild exploitation, with public proof-of-concept exploits appearing within hours of the July 17, 2026 disclosure. Patches are available in WordPress 7.0.2 and 6.9.5; WordPress.org has enabled forced automatic updates across affected supported installations. Background Tenable's Research Special Operations (RSO) team has compiled this blog to answer Frequently Asked Questions (FAQ) regarding wp2shell, two vulnerabilities in WordPress Core that can be chained together to achieve pre-authentication remote code execution. FAQ What is wp2shell? wp2shell is the name given to two vulnerabilities in WordPress Core. When was wp2shell first disclosed? On July 17, 2026, WordPress released security updates addressing the wp2shell vulnerabilities alongside two GitHub Security Advisories. Adam Kues of Searchlight Cyber, who discovered and disclosed CVE-2026-63030, published research on the same day and chose to hold back the technical specifics given the severity of the finding. Searchlight Cyber also launched wp2shell.com , a testing tool that allows administrators to check whether their WordPress installation is vulnerable. On July 20, Searchlight Cyber published a full technical breakdown of the attack chain. What are the vulnerabilities associated with wp2shell? wp2shell is a two-vulnerability exploit chain affecting WordPress Core. CVE Description CVSSv3 CVE-2026-63030 WordPress Core REST API Batch-Route Confusion Remote Code Execution Vulnerability 9.8 CVE-2026-60137 WordPress Core WP_Query author__not_in SQL Injection Vulnerability 5.9 CVE-2026-63030 is a REST API batch-route confusion weakness introduced in WordPress 6.9. CVE-2026-60137 is a SQL injection flaw in the author__not_in parameter of WP_Query , present in WordPress 6.8 and later. When chained on WordPress 6.9.0 through 7.0.1, the two flaws allow an unauthenticated attacker to reach the REST API batch endpoint at /wp-json/batch/v1 and achieve remote code execution. CVE-2026-60137 was discovered and disclosed by security researchers TF1T, dtro, and haongo. CVE-2026-60137 also affects WordPress 6.8.0 through 6.8.5 as a standalone SQL injection issue. Because CVE-2026-63030 was introduced in WordPress 6.9, the full RCE chain is only achievable on 6.9.x and 7.0.x installations. How severe is the wp2shell vulnerability chain? An anonymous, unauthenticated user can execute the chain against a default WordPress installation with no plugins required. No preconditions exist beyond the default WordPress configuration. Cloudflare notes that the vulnerable code path is reached when “a persistent object cache is not in use.” Note: wp2shell targets WordPress Core itself rather than a plugin or theme. All four prior WordPress-related entries in the CISA Known Exploited Vulnerabilities (KEV) catalog involve plugins, not core. Pre-authentication remote code execution in WordPress Core is uncommon. CVE Product Added to KEV Ransomware CVE-2026-41940 WebPros cPanel & WHM and WP2 (WordPress Squared) April 30, 2026 Known CVE-2020-25213 WordPress File Manager Plugin November 3, 2021 Unknown CVE-2020-11738 WordPress Snap Creek Duplicator Plugin November 3, 2021 Unknown CVE-2019-9978 WordPress Social Warfare Plugin November 3, 2021 Unknown How widespread are the attacks exploiting wp2shell? WordPress is the most widely deployed content management system in the world. Some hosted installations will receive patc…
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The wp2shell exploit chain involves two WordPress Core vulnerabilities: CVE-2026-63030, a REST API batch-route confusion vulnerability introduced in WordPress 6.9, and CVE-2026-60137, a SQL injection vulnerability in the author__not_in parameter of WP_Query present since WordPress 6.8. When chained on WordPress versions 6.9.0 through 7.0.1, these allow an unauthenticated attacker to reach the /wp-json/batch/v1 REST API endpoint and achieve remote code execution. CVE-2026-60137 alone affects WordPress 6.8.0 through 6.8.5 as a standalone SQL injection. The exploit requires no plugins or special configuration beyond default WordPress setups without persistent object caching. Multiple security firms have confirmed in-the-wild exploitation, with public proof-of-concept exploits appearing within hours of disclosure. Patches are available in WordPress 6.8.6, 6.9.5, and 7.0.2, and forced automatic updates have been enabled for supported installations. Temporary mitigations include blocking REST API batch endpoint access via plugins or WAF rules. No public attribution or IoCs are currently available.
Potential Impact
An unauthenticated attacker can achieve remote code execution on affected WordPress installations, potentially allowing full system compromise. The exploit chain requires no authentication or plugins and affects default WordPress Core installations from versions 6.9.0 through 7.0.1. The SQL injection vulnerability alone affects versions 6.8.0 through 6.8.5. Active exploitation has been confirmed in the wild shortly after public disclosure, increasing the risk of compromise for unpatched systems.
Mitigation Recommendations
Official patches addressing these vulnerabilities were released on July 17, 2026, and WordPress.org has enabled forced automatic updates for supported affected versions. Users should immediately update to WordPress 6.8.6, 6.9.5, or 7.0.2 or later. For installations unable to update immediately, temporary mitigations include installing plugins that block unauthenticated access to the REST API batch endpoint, blocking /wp-json/batch/v1 and ?rest_route=/batch/v1 at the web application firewall level, or deploying a custom PHP plugin to restrict unauthenticated access to the batch endpoint. Cloudflare has also deployed WAF rules covering these vulnerabilities for proxied sites. These mitigations are interim and do not replace applying the official patches.
Technical Details
- Article Source
- {"url":"https://isc.sans.edu/diary/rss/33168","fetched":true,"fetchedAt":"2026-07-20T22:52:48.922Z","wordCount":498}
- Classification
- {"confidence":0.92,"severitySource":"heuristic","classifier":"rss-v2"}
Indicators of Compromise
Cve
| Value | Description | Copy |
|---|---|---|
cveCVE-2026-63030 | — | |
cveCVE-2026-60137 | — |
Hash
| Value | Description | Copy |
|---|---|---|
hash12de8ce21bc534a968c327c00f2aa933b9034bc39b367ad1659f5aaa8be07744 | — | |
hash37d86716edcb5b481d5d34b38b3bb4b522fcabdf0baf9b0523a0a61957620fad | — | |
hash4f4dc354dfa3ab9df33107b02106424d9940119363ceaff3399aefa8b14859dc | — | |
hash5588eb0d473bbc104ecb7d41037a747280eba03956a3d4c11368e4f0bd427ead | — | |
hash67ce5c125611078c2a6294faacd378b7dccbfb490641a0ca0822b071a22f759c | — | |
hash9c1bf6681ca94ab703d4f393fbfdd0acfb081285cd47ea4cf718ff9b71835722 | — | |
hashd3e34d9306106aca15b1deb6dcfbe169c5f0df470bd22095845d553a60cbfd1e | — | |
hashd4cf7b5d8722236de52e9bad855b4ed4d99f18a561d192aec33525ec89557a7c | — | |
hashd8dfdab3a4358dbcd0eb129494d9e64b8392ef564bdc4cbe73e238c6d3ba51cd | — | |
hashee8395666b9367967749757da27784922fdc18dc3e85db864d30fa703eb9db18 | — | |
hash2a1410d8e2a8337ac2171cedea8c0fdc47c647a0 | — | |
hash58eca847e9eae9e6b08cc211f1559817b71bc4cc | — | |
hashd9a220c8039f1c4d72cae7ccb8b3a33dec8815be | — | |
hashe9756e2338f84746007235e4cab7a70d5b3ca47f | — | |
hashebea44890f434d5d67ede22009a3f4bb5cac33f8 | — |
Ip
| Value | Description | Copy |
|---|---|---|
ip172.235.128.52 | CC=US ASN=AS20940 akamai international b.v. | |
ip79.177.131.206 | CC=IL ASN=AS8551 bezeq international-ltd | |
ip94.100.52.128 | CC=RS ASN=AS47588 tel communications l.l.c. |
Threat ID: 6a5ea6c92a4a8d5989e4741c
Added to database: 07/20/2026, 22:52:57 UTC
Last enriched: 08/07/2026, 05:44:39 UTC
Last updated: 09/04/2026, 10:52:10 UTC
Views: 225
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.