SECURITYTHE REGISTER
Attackers pummel critical WordPress vuln to create all sorts of mischief
Attackers are exploiting two critical WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) to enable pre-authentication remote code execution. The flaws, patched in WordPress versions 6.9.5 and 7.1 Beta 2, allow unauthenticated users to execute arbitrary code by chaining an SQL injection issue with a REST API route confusion bug. Security researchers observed widespread exploitation within hours of the patches being released.
Mentioned
Related Signal
Adjacent reporting
- WordPress Core "wp2shell" RCE flaws get public exploits, patch now
- 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
- Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
- AI agents found vulns in this popular Linux and Unix print server