WordPress released security updates for two core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, that can be chained to make a blind SQL injection remotely reachable without authentication and, in some cases, lead to remote code execution. The issue, dubbed wp2shell, stems from REST API batch-route confusion in the /wp-json/batch/v1 endpoint combined with SQL injection, affecting WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. Researchers said the route-confusion flaw carries a CVSS 9.8 rating, while the second SQL injection bug is rated CVSS 5.9.
WordPress fixed the flaws in 6.9.5 and 7.0.2, and also backported the SQL injection fix to 6.8.6. The vulnerabilities were reported by Adam Kues of Assetnote through the WordPress HackerOne program, and while exploitation had not been confirmed at the time of disclosure, a public proof of concept later became available, increasing the risk of rapid weaponization. Administrators were urged to verify that forced automatic updates succeeded and, if immediate patching was not possible, to apply mitigations such as blocking the REST batch endpoint with a WAF.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On July 21, 2026, ISA added CVE-2026-63030 to its Known Exploited Vulnerabilities Catalog after in-the-wild exploitation of the WP2Shell chain was confirmed. The listing accelerated remediation requirements for U.S. federal agencies.
As of 17 July, no active exploitation of the WordPress vulnerabilities had been confirmed. Researchers warned, however, that public patch diffs could quickly enable proof-of-concept exploit development.
A public proof of concept became available showing how CVE-2026-60137 and CVE-2026-63030 could be chained for unauthenticated exploitation. The PoC demonstrated a path to sensitive database extraction and, in some conditions, arbitrary code execution.
WordPress released fixes for the affected branches, patching CVE-2026-63030 in versions 6.9.5 and 7.0.2 and addressing CVE-2026-60137 with backports including 6.8.6. The vulnerabilities affected WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.
Adam Kues of Assetnote discovered the WordPress Core vulnerabilities CVE-2026-63030 and CVE-2026-60137 through the WordPress HackerOne program. The flaws could be chained to make a blind SQL injection remotely reachable without authentication and potentially lead to remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
fortiguard.fortinet.com
Open sourcethecyberexpress.com
Open sourceboho.or.kr
Open sourceacn.gov.it
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.