- Sources: Searchlight Cyber research, CVE-2026-63030 (NVD), Rapid7 analysis
- Summary: Searchlight Cyber disclosed wp2shell on 2026-07-17, an unauthenticated remote code execution chain in WordPress core that needs no plugins and no user account. CVE-2026-63030 is a route-confusion flaw in the REST API batch endpoint (
/wp-json/batch/v1) chained with CVE-2026-60137, a SQL injection, to reach code execution on a stock install. Affected versions are 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. WordPress shipped 6.9.5 and 7.0.2 on 2026-07-17 and is forcing updates on installs that have automatic updates enabled. A public proof of concept for CVE-2026-63030 exists. No active exploitation is reported as of 2026-07-18. - Why it matters: WordPress runs a large share of public websites, so a no-precondition core RCE with a public proof of concept puts every unpatched internet-facing install at direct risk.
- Follow-up: Watch for active exploitation and mass scanning, a CISA KEV addition, and confirmation that forced auto-updates reach installs that do not have auto-update enabled.
send feedback on this story