
WordPress serves millions of websites worldwide, from small businesses to the marketing sites of large fortune 500 companies. Here at Raxis, we often perform penetration tests of WordPress sites for our clients, so we stay on top of the latest WordPress vulnerabilities and exploits.
Most WordPress issues stem from insecure or out of date plugins. It is rare to see a CVE issued directly to WordPress itself, especially one that results in unauthenticated code execution.
The CVEs
CVE-2026-63030 and CVE-2026-60137 combine into the exploit known as wp2shell. An exploit chain that gets you from unauthenticated visitor to running code on the affected server. Thankfully, the researchers that identified this vulnerability worked with WordPress to get this patched in WordPress versions 6.9.5 and 7.0.2.
WordPress initiated automatic updates to WordPress installations to ensure they got patched. In fact, while researching the proof of concept exploit my own WordPress installation updated during testing.
What You Can Do Now
If you or your organization uses WordPress, Raxis recommends enabling automatic updates, and ensuring that your WordPress has been updated to the latest version to patch this critical unauthenticated vulnerability.
If you have an instance of WordPress running an affected version that has not been patched, install the patch immediately or implement the mitigations suggested in the wp2shell security advisory. You should also consider your WordPress credentials compromised and force a password reset for every WordPress user account in the affected site.

Jason Taylor
About The Exploit
The Exploit is written by Raxis penetration testers. Every post is a technical writeup from someone who runs engagements for a living, with code, command output, and the reasoning behind each step. Topics include exploit research, vulnerability disclosure, tool development, and the offensive techniques showing up in current client work.
Raxis Discovered Vulnerabilities
View the CVEs and bugs that Raxis pentesters have uncovered and submitted.
Work With the Pentesters Who Wrote This Blog
The engineers behind these posts run real engagements every week. Put them on your network, web apps, APIs, or cloud and see what an attacker would find first.
Blog Categories
- AI
- Careers
- Choosing a Penetration Testing Company
- Exploits
- How To
- In The News
- Injection Attacks
- Just For Fun
- Meet Our Team
- Mobile Apps
- Networks
- Password Cracking
- Patching
- Penetration Testing
- Phishing
- PTaaS
- Raxis Discovered Vulnerabilities
- Raxis In The Community
- Red Team
- Security Recommendations
- Social Engineering
- Tips For Everyone
- Web Apps
- What People Are Saying
- Wireless
