wp2shell: Critical WordPress Unauthenticated to Remote Code Execution Vulnerability

The Exploit Blog

Penetration Testing Blog

wp2shell: Critical WordPress Unauthenticated to Remote Code Execution Vulnerability
Published on July 30, 2026
Written by Jason Taylor

WordPress serves millions of websites worldwide, from small businesses to the marketing sites of large fortune 500 companies. Here at Raxis, we often perform penetration tests of WordPress sites for our clients, so we stay on top of the latest WordPress vulnerabilities and exploits.

Most WordPress issues stem from insecure or out of date plugins. It is rare to see a CVE issued directly to WordPress itself, especially one that results in unauthenticated code execution.

The CVEs

CVE-2026-63030 and CVE-2026-60137 combine into the exploit known as wp2shell. An exploit chain that gets you from unauthenticated visitor to running code on the affected server. Thankfully, the researchers that identified this vulnerability worked with WordPress to get this patched in WordPress versions 6.9.5 and 7.0.2. 

WordPress initiated automatic updates to WordPress installations to ensure they got patched. In fact, while researching the proof of concept exploit my own WordPress installation updated during testing. 

What You Can Do Now

If you or your organization uses WordPress, Raxis recommends enabling automatic updates, and ensuring that your WordPress has been updated to the latest version to patch this critical unauthenticated vulnerability. 

If you have an instance of WordPress running an affected version that has not been patched, install the patch immediately or implement the mitigations suggested in the wp2shell security advisory. You should also consider your WordPress credentials compromised and force a password reset for every WordPress user account in the affected site.

Jason Taylor

Jason Taylor

Jason has a passion for asking “what-if” questions and for trying to “break” software and test how it responds to unintended uses. Jason has a background in System Administration and Security Engineering in the financial sector. He holds both defensive and offensive certifications including OSCP, PNPT, GCIH, CASP+, and is Splunk Certified. When he’s not spending his time taking new training courses, he loves spending time with his wife and kids and occasionally working on an IoT project to automate some aspect of their greenhouse or chicken coop.
Search The Exploit Blog

About The Exploit

The Exploit is written by Raxis penetration testers. Every post is a technical writeup from someone who runs engagements for a living, with code, command output, and the reasoning behind each step. Topics include exploit research, vulnerability disclosure, tool development, and the offensive techniques showing up in current client work.

Raxis Discovered Vulnerabilities

View the CVEs and bugs that Raxis pentesters have uncovered and submitted.

Work With the Pentesters Who Wrote This Blog

The engineers behind these posts run real engagements every week. Put them on your network, web apps, APIs, or cloud and see what an attacker would find first.

Join Our Newsletter

Name(Required)
Newsletter(Required)
Do you wish to join our newsletter? We send out emails once a month that cover the latest in cybersecurity news. We do not sell your information to other parties.