WordPress released 7.0.2 to fix two core vulnerabilities that can be chained into unauthenticated remote code execution, including CVE-2026-63030 and CVE-2026-60137. The flaws affect default WordPress installations without plugins, with the RCE path impacting 6.9.0 through 6.9.4, 7.0.0 through 7.0.1, and 7.1 beta, while the SQL injection issue also affects the 6.8 branch. WordPress issued backported fixes in 6.9.5, 6.8.6, and 7.1 Beta 2, enabled forced auto-updates for affected sites, and said the attack chain abuses the REST API batch endpoint to trigger route confusion, bypass request handling restrictions, and reach SQL injection that can lead to full site compromise.
Security vendors moved quickly to contain exposure as public technical details began to emerge. Cloudflare deployed WAF protections for both CVEs for all customers and Wordfence added firewall coverage for premium users, but both stressed that filtering is only a temporary mitigation and that patching is the primary remediation. Researchers attributed the discovery to Adam Kues of Searchlight Cyber's Assetnote team, and while early reporting said no in-the-wild exploitation had been confirmed, a public GitHub proof of concept later demonstrated unauthenticated access to the vulnerable batch endpoint and blind SQL injection against affected versions, increasing the likelihood of rapid attacker weaponization.

See affected versions and whether adversaries are exploiting it.
17 events from the most recent confirmed update back to the earliest known activity.
A ProjectDiscovery Nuclei templates pull request updated CVE-2026-63030 detection logic by replacing a timing-based blind SQL injection check with a deterministic route-confusion probe. The change was intended to reduce false negatives, avoid WAF-related flakiness, and lessen availability impact while keeping a WordPress pre-check to limit false positives.
A Rapid7 Metasploit Framework pull request published an auxiliary scanner module for the WordPress wp2shell chain that verifies the route-confusion primitive, confirms time-based blind SQL injection, and can extract WordPress usernames and password hashes. Unlike the previously noted draft RCE module, this module is described as read-only and does not create content on the target site.
A Rapid7 Metasploit Framework pull request published a draft module, `exploit/multi/http/wp_batch_desync_rce`, for exploiting the WordPress wp2shell chain involving CVE-2026-63030 and CVE-2026-60137. The module automates SQL injection-based discovery, administrator account creation, malicious plugin upload, Meterpreter session establishment, and cleanup steps.
On 2026-07-20, Wiz reported observed exploitation of vulnerable self-hosted WordPress instances in cloud environments and described post-compromise activity including malicious plugin uploads, user enumeration, local file inclusion attempts for wp-config data, and admin-panel access. The report also documented multiple PHP webshell/plugin variants and highlighted detection indicators such as requests to batch REST API endpoints, HTTP 207/200 Multi-Status responses, and user agents containing "wp2shell" or "rezwp2shell."
By early 2026-07-19, multiple security researchers reported broad exploitation of the WordPress wp2shell chain, including credential exfiltration, creation of backdoor administrator accounts, and deployment of malicious plugins. The reporting also described tens of thousands of attack attempts and more than two dozen public proof-of-concept exploits circulating after disclosure.
A defender-focused wp2shell guide was published describing forensic artifacts for compromise assessment and incident response. The release also promoted a WordPress compromise scanner plugin and a browser extension for checking whether sites had been patched.
A Fortbridge research post publicly detailed how CVE-2026-63030 and CVE-2026-60137 can be chained on a default WordPress installation to achieve unauthenticated PHP code execution. The write-up described route-confusion bypass, SQL injection, administrator account creation without cracking hashes, plugin upload, and direct execution, along with detection and mitigation guidance.
On 2026-07-21, CISA added CVE-2026-63030 to its Known Exploited Vulnerabilities catalog and marked the WordPress flaw as actively exploited, automatable, and having total technical impact. The listing elevated the vulnerability's status beyond prior researcher and vendor exploitation reports.
BleepingComputer reported that watchTowr observed early signs of in-the-wild exploitation targeting the public 'wp2shell' WordPress flaw chain after exploit code became available. This marked an escalation from public proof-of-concept release to apparent real-world attack activity.
On 2026-07-18, a GitHub repository published independent proof-of-concept code for exploiting the unauthenticated route-confusion SQL injection in the WordPress REST batch endpoint. The repository demonstrated database-read and blind SQL injection techniques but did not claim to reproduce Searchlight Cyber's undisclosed pre-authentication RCE path.
Wordfence stated it deployed firewall protection for premium customers on 2026-07-17 for the WordPress vulnerability chain. The same protection was scheduled for free users on 2026-08-16, but that future rollout is not treated as an event date here.
On 2026-07-17, a ProjectDiscovery Nuclei templates pull request added and updated a detection template for WordPress wp2shell. The changes included advisory references and template metadata updates.
Cloudflare deployed blocking WAF rules for CVE-2026-60137 and CVE-2026-63030 on 2026-07-17 at 17:03 UTC for customers. The company described the protections as a temporary mitigation and urged users to patch WordPress.
A GitHub Security Advisory published on 2026-07-17 disclosed CVE-2026-63030 as a critical unauthenticated remote code execution vulnerability in WordPress Core. The advisory identified affected versions and the patched releases.
On 2026-07-17, WordPress disclosed and patched two core vulnerabilities, CVE-2026-60137 and CVE-2026-63030, releasing fixes in 7.0.2, 6.9.5, 6.8.6, and 7.1 Beta 2. The issues could be chained into unauthenticated remote code execution on affected versions, and WordPress enabled forced automatic updates for vulnerable installations.
Elastic Security Labs published defender guidance for detecting the wp2shell WordPress pre-auth RCE chain, describing lab-observed Linux host artifacts such as web server child processes spawning shells, plugin-directory file creation, and recognizable access-log markers from public tooling. The article mapped the attack chain to Elastic Defend and SIEM detections and advised defenders to patch immediately and treat exposed vulnerable instances as potentially compromised.
A Wordfence-cited report said its firewall had blocked more than 11 million exploit attempts targeting the WordPress wp2shell chain. The attacks sought to chain CVE-2026-63030 and CVE-2026-60137 to create rogue administrator accounts on vulnerable sites, providing a new quantitative measure of the campaign's scale.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 25 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
50 references tracked. Mallory keeps watching after this page renders.
mbsd.jp
Open sourcetrustedsec.com
Open sourcegithub.com
Open sourcefortiguard.fortinet.com
Open sourceresearch.eye.security
Open sourcefortbridge.co.uk
Open sourcewordfence.com
Open sourcewp2shell.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.