THREAT OPS › Threat News › CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core
<p></p><h2 style="direction: ltr;"><span style="font-size: undefined;">Overview</span></h2><p style="direction: ltr;"><span style="font-size: undefined;">On July 17, 2026, a GitHub Security Advisory was </span><a href="https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q"><span style="font-size: undefined;">published</span></a><span style="font-size: undefined;">
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2026-63030cve
- CVE-2026-60137cve
- https://wordpress.org/news/2026/07/wordpress-7-0-2-release/url
- https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/url
- https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/url