run WordPress? stop and update right now — this bug hands your entire site to a stranger

no login. no plugin. no weird setup. one anonymous request and a stranger owns a default WordPress site. the fix is out — here's exactly what to…

Aliteq
Priya Nair · Software & Systems Editor

wp2shell in brief

What it is: a critical WordPress core RCE chaining CVE-2026-63030 (REST API route confusion) and CVE-2026-60137 (SQL injection). No login, no plugin, default install.

wp2shell in brief

Affected: WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1. Fixed in 6.9.5 / 7.0.2 — update now.

wp2shell in brief

Rated CVSS 9.8 and exploited in the wild within a day of disclosure.

wp2shell in brief

This is rare: 96% of WordPress bugs are in plugins, not core — which is why this one warranted a forced update.

Discovered by Adam Kues at Assetnote (Searchlight Cyber), reported through WordPress's HackerOne program — the kind of responsible disclosure that got a fix shipped before mass exploitation, not…

Aliteq

Read the full story

run WordPress? stop and update right now — this bug hands your entire site to a stranger

Read the full story on Aliteq