Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-07-18 ยท updated: 2026-07-18 ยท tags: [cve, wordpress, rest-api, rce, poc] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, media, retail, government] ยท au_impact: true

CVE-2026-63030 ("wp2shell" chain)

CVE-2026-63030 is a REST API batch-route confusion vulnerability in WordPress core, chained with CVE-2026-60137 (SQL injection) to allow unauthenticated remote code execution on any WordPress 6.9/7.0 site โ€” the disclosure publicly dubbed "wp2shell".

Attribute Detail
CVE CVE-2026-63030 (REST API batch-route confusion)
Chained with CVE-2026-60137 (SQL injection)
Impact Anonymous RCE on any 6.9/7.0 site
Fix WordPress 6.9.5 / 7.0.2 (forced auto-updates)
Researcher Adam Kues (Assetnote / Searchlight Cyber)
PoC Public on GitHub
Source The Hacker News โ€” Tier 2/4

A working proof-of-concept is public on GitHub, making unpatched WordPress sites a high-priority patch-and-audit target.

Source