The Exploit

In The News

wp2shell: Critical WordPress Unauthenticated to Remote Code Execution Vulnerability

wp2shell: Critical WordPress Unauthenticated to Remote Code Execution Vulnerability

WordPress serves millions of websites worldwide, from small businesses to the marketing sites of large fortune 500 companies. Here at Raxis, we often perform penetration tests of WordPress sites for our clients, so we stay on top of the latest WordPress vulnerabilities and exploits.

Most WordPress issues stem from insecure or out of date plugins. It is rare to see a CVE issued directly to WordPress itself, especially one that results in unauthenticated code execution.

The CVEs

CVE-2026-63030 and CVE-2026-60137 combine into the exploit known as wp2shell. An exploit chain that gets you from unauthenticated visitor to running code on the affected server. Thankfully, the researchers that identified this vulnerability worked with WordPress to get this patched in WordPress versions 6.9.5 and 7.0.2. 

WordPress initiated automatic updates to WordPress installations to ensure they got patched. In fact, while researching the proof of concept exploit my own WordPress installation updated during testing. 

What You Can Do Now

If you or your organization uses WordPress, Raxis recommends enabling automatic updates, and ensuring that your WordPress has been updated to the latest version to patch this critical unauthenticated vulnerability. 

If you have an instance of WordPress running an affected version that has not been patched, install the patch immediately or implement the mitigations suggested in the wp2shell security advisory. You should also consider your WordPress credentials compromised and force a password reset for every WordPress user account in the affected site.

Keep Reading

Request a quote

Tell Us What You Need Tested

We usually respond in one business day.

Please let us know what's on your mind. Include any details about your target environment, timeline, or compliance drivers.