WordPress released 7.0.2 to fix two core vulnerabilities that can be chained into unauthenticated remote code execution, including CVE-2026-63030 and CVE-2026-60137. The flaws affect default WordPress installations without plugins, with the RCE path impacting 6.9.0 through 6.9.4, 7.0.0 through 7.0.1, and 7.1 beta, while the SQL injection issue also affects the 6.8 branch. WordPress issued backported fixes in 6.9.5, 6.8.6, and 7.1 Beta 2, enabled forced auto-updates for affected sites, and said the attack chain abuses the REST API batch endpoint to trigger route confusion, bypass request handling restrictions, and reach SQL injection that can lead to full site compromise.
Security vendors moved quickly to contain exposure as public technical details began to emerge. Cloudflare deployed WAF protections for both CVEs for all customers and Wordfence added firewall coverage for premium users, but both stressed that filtering is only a temporary mitigation and that patching is the primary remediation. Researchers attributed the discovery to Adam Kues of Searchlight Cyber's Assetnote team, and while early reporting said no in-the-wild exploitation had been confirmed, a public GitHub proof of concept later demonstrated unauthenticated access to the vulnerable batch endpoint and blind SQL injection against affected versions, increasing the likelihood of rapid attacker weaponization.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
A Rapid7 Metasploit Framework pull request published an auxiliary scanner module for the WordPress wp2shell chain that verifies the route-confusion primitive, confirms time-based blind SQL injection, and can extract WordPress usernames and password hashes. Unlike the previously noted draft RCE module, this module is described as read-only and does not create content on the target site.
A Rapid7 Metasploit Framework pull request published a draft module, `exploit/multi/http/wp_batch_desync_rce`, for exploiting the WordPress wp2shell chain involving CVE-2026-63030 and CVE-2026-60137. The module automates SQL injection-based discovery, administrator account creation, malicious plugin upload, Meterpreter session establishment, and cleanup steps.
On 2026-07-20, Wiz reported observed exploitation of vulnerable self-hosted WordPress instances in cloud environments and described post-compromise activity including malicious plugin uploads, user enumeration, local file inclusion attempts for wp-config data, and admin-panel access. The report also documented multiple PHP webshell/plugin variants and highlighted detection indicators such as requests to batch REST API endpoints, HTTP 207/200 Multi-Status responses, and user agents containing "wp2shell" or "rezwp2shell."
By early 2026-07-19, multiple security researchers reported broad exploitation of the WordPress wp2shell chain, including credential exfiltration, creation of backdoor administrator accounts, and deployment of malicious plugins. The reporting also described tens of thousands of attack attempts and more than two dozen public proof-of-concept exploits circulating after disclosure.
A defender-focused wp2shell guide was published describing forensic artifacts for compromise assessment and incident response. The release also promoted a WordPress compromise scanner plugin and a browser extension for checking whether sites had been patched.
A Fortbridge research post publicly detailed how CVE-2026-63030 and CVE-2026-60137 can be chained on a default WordPress installation to achieve unauthenticated PHP code execution. The write-up described route-confusion bypass, SQL injection, administrator account creation without cracking hashes, plugin upload, and direct execution, along with detection and mitigation guidance.
On 2026-07-21, CISA added CVE-2026-63030 to its Known Exploited Vulnerabilities catalog and marked the WordPress flaw as actively exploited, automatable, and having total technical impact. The listing elevated the vulnerability's status beyond prior researcher and vendor exploitation reports.
BleepingComputer reported that watchTowr observed early signs of in-the-wild exploitation targeting the public 'wp2shell' WordPress flaw chain after exploit code became available. This marked an escalation from public proof-of-concept release to apparent real-world attack activity.
On 2026-07-18, a GitHub repository published independent proof-of-concept code for exploiting the unauthenticated route-confusion SQL injection in the WordPress REST batch endpoint. The repository demonstrated database-read and blind SQL injection techniques but did not claim to reproduce Searchlight Cyber's undisclosed pre-authentication RCE path.
Wordfence stated it deployed firewall protection for premium customers on 2026-07-17 for the WordPress vulnerability chain. The same protection was scheduled for free users on 2026-08-16, but that future rollout is not treated as an event date here.
On 2026-07-17, a ProjectDiscovery Nuclei templates pull request added and updated a detection template for WordPress wp2shell. The changes included advisory references and template metadata updates.
Cloudflare deployed blocking WAF rules for CVE-2026-60137 and CVE-2026-63030 on 2026-07-17 at 17:03 UTC for customers. The company described the protections as a temporary mitigation and urged users to patch WordPress.
A GitHub Security Advisory published on 2026-07-17 disclosed CVE-2026-63030 as a critical unauthenticated remote code execution vulnerability in WordPress Core. The advisory identified affected versions and the patched releases.
On 2026-07-17, WordPress disclosed and patched two core vulnerabilities, CVE-2026-60137 and CVE-2026-63030, releasing fixes in 7.0.2, 6.9.5, 6.8.6, and 7.1 Beta 2. The issues could be chained into unauthenticated remote code execution on affected versions, and WordPress enabled forced automatic updates for vulnerable installations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcethehackernews.com
Open sourcesecurityonline.info
Open sourcexakep.ru
Open sourcegithub.com
Open sourcecve.circl.lu
Open sourcewp2shell.com
Open sourcewordfence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.