THREAT OPS › Threat News › wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core
<p><strong>An unauthenticated attacker can chain two WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to achieve remote code execution against affected WordPress installations. Multiple security firms have confirmed active in-the-wild exploitation within days of public disclosure, and public proof-of-concept exploits are circulating.</strong></p><div class="blog-see-also"><h2>Key
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- CVE-2026-63030cve
- CVE-2026-60137cve
- CVE-2026-41940cve
- CVE-2020-25213cve
- CVE-2020-11738cve
- CVE-2019-9978cve
- https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core/url
- https://wp2shell.com/url
- https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/url
- https://t.co/VkNcCVwcLVurl
- https://t.co/iuU0yiYJBTurl
- https://wordpress.org/news/2026/07/wordpress-7-0-2-release/url
- https://connect.tenable.com/category/news-you-need/discussions/vulnerability-watchurl