THREAT OPS › Threat News › wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade
wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade
<div> <p style="margin: 0 0 1.1em; line-height: 1.65; color: #1a1a2e;">On Friday, July 17, 2026, the WordPress Security Team released <a href="https://wordpress.org/news/2026/07/wordpress-7-0-2-release/" rel="noopener noreferrer" style="color: #00709e;" target="_blank">security updates</a> for WordPress Core addressing two vulnerabilities that, when chained together, can lead to unauthenticated re
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
- Malicious LinkT1204.001
- Malicious LinkAML.T0011.003
Indicators of compromise
- CVE-2026-60137cve
- CVE-2026-63030cve
- https://wordpress.org/news/2026/07/wordpress-7-0-2-release/url
- https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/url
- https://wp2shell.com/url