Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-07-18 ยท updated: 2026-07-21 ยท tags: [cve, zero-day, web-shell, supply-chain] ยท confidence: high ยท severity: not-rated ยท affected_sectors: [technology, government, media, education] ยท au_impact: true

wp2shell โ€” WordPress Core RCE

wp2shell refers to two chained vulnerabilities in WordPress core (versions 6.9 and 7.0) that allow unauthenticated remote code execution on every affected site. Emergency patches were shipped with forced auto-updates enabled.

CVEs

CVE Type CVSS (est.) Notes
CVE-2026-63030 REST API batch-route confusion High Allows attacker to bypass route access controls
CVE-2026-60137 SQL injection Critical Enables database-level exploitation when chained

Exploitation Status (Updated 2026-07-21)

  • Mass scanning underway: Telemetry from KEVIntel shows 13 unique IP addresses conducting mass scanning
  • Geography of scanners: Switzerland, Germany, UK, Indonesia, Lithuania, Netherlands, Singapore
  • Post-exploitation: Credential exfiltration and RCE following exploitation confirmed
  • Public PoC: Released early Saturday (July 18), triggering rapid escalation (raw/digests/Cyber-Digest-2026-07-21)

Impact

  • Every WordPress 6.9 and 7.0 site is vulnerable prior to patching
  • Unauthenticated RCE via chaining the two flaws
  • A working Proof of Concept is now public on GitHub (raw/digests/Cyber-Digest-2026-07-18)

Response

  • WordPress shipped emergency patches 6.9.5 and 7.0.2
  • Forced auto-updates enabled to push patches to all sites
  • Disclosure and patch timeline: July 18, 2026

Australian Significance

WordPress powers a significant portion of Australian government, media, and small business websites โ€” approximately 36% of Australian websites per W3Techs data. The forced auto-update mechanism helps protect the long tail of unmanaged WordPress sites, but many Australian organisations disable auto-updates due to change management policies, leaving them exposed.

The ACSC has not issued a specific advisory on wp2shell as of late July 2026, but the vulnerability falls within the scope of their CMS exploitation campaign alert (AA-2026-XX), which reinforces that CMS platforms are a priority target for both cybercriminals and state-sponsored actors targeting Australian entities.

The public PoC increases exploitation risk for sites that cannot receive auto-updates or have custom configurations. Australian enterprises running customised WordPress deployments should treat WordPress core updates with the same urgency as OS patches. Au Impact

Related Pages

  • Acsc Cms Exploitation โ€” Concurrent large-scale CMS exploitation campaign targeting AU orgs
  • Wp Shellstorm โ€” Webshell brokerage exploiting outdated CMS plugins