type: cve ยท created: 2026-07-18 ยท updated: 2026-07-18 ยท tags: [cve, wordpress, sql-injection, rce, poc] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, media, retail, government] ยท au_impact: true
CVE-2026-60137 ("wp2shell" chain)
CVE-2026-60137 is a SQL injection vulnerability in WordPress core, chained with CVE-2026-63030 (REST API batch-route confusion) to allow unauthenticated remote code execution on any WordPress 6.9/7.0 site โ the disclosure publicly dubbed "wp2shell".
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-60137 (SQL injection) |
| Chained with | CVE-2026-63030 (REST API batch-route confusion) |
| Impact | Anonymous RCE on any 6.9/7.0 site |
| Fix | WordPress 6.9.5 / 7.0.2 (forced auto-updates) |
| Researcher | Adam Kues (Assetnote / Searchlight Cyber) |
| PoC | Public on GitHub |
| Source | The Hacker News โ Tier 2/4 |
A working proof-of-concept is now public on GitHub, making unpatched WordPress sites a high-priority patch-and-audit target.