wp2shell โ WordPress Core RCE
wp2shell refers to two chained vulnerabilities in WordPress core (versions 6.9 and 7.0) that allow unauthenticated remote code execution on every affected site. Emergency patches were shipped with forced auto-updates enabled.
CVEs
| CVE | Type | CVSS (est.) | Notes |
|---|---|---|---|
| CVE-2026-63030 | REST API batch-route confusion | High | Allows attacker to bypass route access controls |
| CVE-2026-60137 | SQL injection | Critical | Enables database-level exploitation when chained |
Exploitation Status (Updated 2026-07-21)
- Mass scanning underway: Telemetry from KEVIntel shows 13 unique IP addresses conducting mass scanning
- Geography of scanners: Switzerland, Germany, UK, Indonesia, Lithuania, Netherlands, Singapore
- Post-exploitation: Credential exfiltration and RCE following exploitation confirmed
- Public PoC: Released early Saturday (July 18), triggering rapid escalation (raw/digests/Cyber-Digest-2026-07-21)
Impact
- Every WordPress 6.9 and 7.0 site is vulnerable prior to patching
- Unauthenticated RCE via chaining the two flaws
- A working Proof of Concept is now public on GitHub (raw/digests/Cyber-Digest-2026-07-18)
Response
- WordPress shipped emergency patches 6.9.5 and 7.0.2
- Forced auto-updates enabled to push patches to all sites
- Disclosure and patch timeline: July 18, 2026
Australian Significance
WordPress powers a significant portion of Australian government, media, and small business websites โ approximately 36% of Australian websites per W3Techs data. The forced auto-update mechanism helps protect the long tail of unmanaged WordPress sites, but many Australian organisations disable auto-updates due to change management policies, leaving them exposed.
The ACSC has not issued a specific advisory on wp2shell as of late July 2026, but the vulnerability falls within the scope of their CMS exploitation campaign alert (AA-2026-XX), which reinforces that CMS platforms are a priority target for both cybercriminals and state-sponsored actors targeting Australian entities.
The public PoC increases exploitation risk for sites that cannot receive auto-updates or have custom configurations. Australian enterprises running customised WordPress deployments should treat WordPress core updates with the same urgency as OS patches. Au Impact
Related Pages
- Acsc Cms Exploitation โ Concurrent large-scale CMS exploitation campaign targeting AU orgs
- Wp Shellstorm โ Webshell brokerage exploiting outdated CMS plugins