07/24/2026🔴 Critical

Emergency Alert: wp2shell Pre-Auth RCE in WordPress Core Demands Immediate Action

The wp2shell vulnerability chain (CVE-2026-63030 & CVE-2026-60137) allows unauthenticated RCE on default WordPress installs. Learn how to secure your business site now.

⚠️ This vulnerability is being actively exploited in the wild — patch immediately.
🔴 Critical✅ Official patch available

Affected platforms

References

Emergency Alert: wp2shell Pre-Auth RCE in WordPress Core Demands Immediate Action

The global cybersecurity community is facing a massive security storm this week following the disclosure of a critical pre-authentication Remote Code Execution (RCE) vulnerability chain named "wp2shell" in WordPress Core. This flaw represents a worst-case scenario for business owners, as it allows attackers to compromise websites without requiring any user interaction or valid credentials, affecting the core software itself rather than third-party plugins.

Executive summary

  • The wp2shell vulnerability chain (CVSS 9.8) is a critical security flaw residing directly in WordPress Core, meaning default installations with zero plugins are fully exposed.
  • Anonymous, unauthenticated attackers can exploit this chain to execute arbitrary code and gain full control over the target website and its underlying database.
  • Active exploitation in the wild has been confirmed; the U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially added these vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on July 21, 2026.
  • While WordPress triggered forced automatic updates, organizations must manually verify their versions as updates are frequently blocked or disabled in enterprise environments.

What happened?

Discovered by Searchlight Cyber and disclosed on July 17, 2026, wp2shell is a highly dangerous exploit chain. It combines CVE-2026-63030 (a REST API batch route confusion vulnerability) with CVE-2026-60137 (a SQL injection vulnerability in WP_Query). The vulnerability affects WordPress Core versions 6.9.0 through 6.9.4, and 7.0.0 through 7.0.1. Patches have been backported and released in versions 7.0.2, 6.9.5, and 6.8.6.

How the attack works at a high level

The attack targets the WordPress REST API batch endpoint, which is designed to bundle multiple API requests into one. Due to a routing desynchronization flaw, an unauthenticated attacker can bypass parameter sanitization checks. By chaining this with an unescaped query parameter in the database layer, the attacker triggers a SQL injection. This allows them to extract database contents, forge administrator accounts, and eventually upload malicious scripts (webshells) to achieve remote code execution.

Why this is a business risk

WordPress powers over 43% of all websites globally. Because this flaw resides in the core code rather than a third-party plugin, every unpatched site is a potential target. The business impact is severe: complete data breaches, customer credential theft, SEO spam injection, and server hijacking. Furthermore, because the patch was dropped on a Friday afternoon, attackers capitalized on the weekend gap to release dozens of public proof-of-concept exploits, leaving unprepared IT teams highly vulnerable.

What businesses should do in the next 24–72 hours

  • Immediately audit all corporate WordPress installations and verify they are running version 7.0.2, 6.9.5, or 6.8.6 (or newer). Do not assume auto-updates succeeded.
  • Inspect web server access logs for suspicious requests targeting the REST API batch endpoint (/wp-json/batch/v1 or /?rest_route=/batch/v1).
  • Review the database's administrator user table for any unauthorized accounts created on or after July 17, 2026.
  • Ensure your Web Application Firewall (WAF) rules (e.g., Cloudflare, Akamai) are updated and actively blocking wp2shell exploit patterns.
  • Perform a full system backup and store it in an isolated, off-site location.

Long-term lessons for CMS and digital infrastructure security

The wp2shell crisis highlights the critical need for proactive security management. Relying solely on vendor auto-updates is a risky strategy. Organizations must establish robust patch management workflows, continuous security monitoring, and layered defenses like WAFs and CDNs. Partnering with an experienced technical team ensures that your digital assets are monitored, backed up, and secured against zero-day threats.

How Hanoi Byte can help

If your business relies on WordPress, a custom CMS, or cloud-based digital infrastructure, Hanoi Byte can help you assess risks, modernize your systems, and build a practical security and maintenance roadmap. We specialize in digital transformation, cloud optimization, and secure software development tailored to your operational needs. Contact Hanoi Byte today to start a conversation about making your digital operations more secure, scalable, and resilient.

Contact Us