WordPress Core RCE flaws get public exploits, patch now
Security researchers have disclosed two high-severity remote code execution vulnerabilities in WordPress Core, collectively dubbed "wp2shell." Public exploit code has already been released, prompting urgent calls for site owners to patch immediately. The flaws allow unauthenticated attackers to execute arbitrary code on vulnerable WordPress installations, potentially leading to full site compromise.
The vulnerabilities affect all versions of WordPress Core prior to the latest security release. Any WordPress site running an unpatched version is at risk, including millions of blogs, business sites, and e-commerce stores worldwide. The flaws are particularly dangerous because they require no authentication, meaning any attacker can exploit them over the internet.
These are critical because they enable remote code execution, giving attackers complete control over the server. Attackers could steal data, install malware, deface sites, or use compromised servers for further attacks. Given WordPress powers over 40% of the web, the potential impact is massive.
According to the source, the vulnerabilities are tracked as CVE-2026-63030 and another identifier, with a CVSS score of 9.8 (critical). The flaws involve SQL injection that leads to remote code execution. Public proof-of-concept exploits have been published on GitHub and other platforms, increasing the urgency for patching.
WordPress released a security update on [date not specified in source] to address these issues. However, many sites have not yet applied the patch. Security firms including Cloudflare, Rapid7, and Aikido Security have published advisories urging immediate action. Cloudflare noted that its Web Application Firewall can protect against exploitation.
Site administrators are strongly advised to update WordPress Core to the latest version immediately. Those unable to update should consider using a web application firewall or other security measures to block exploit attempts. Continued monitoring for signs of compromise is recommended, as active scanning for vulnerable sites is likely underway.
Sources
- Google News TechnologySecondary
- Google News GlobalSecondary
Related
Cyera acquires Oasis Security for $1B in third deal this year
ChatGPT hack overwhelms tech firm, emergency call held
Microsoft unveils AI security tools it says outperform competing platforms
Private Claude chats exposed in Google and Bing search results
Apple sued after alleged App Store crypto scam cost users $1.8M
Microsoft unveils cybersecurity AI tools
Claude AI shared chats indexed by Google before removal
Hugging Face CEO urges transparency after 'unprecedented' OpenAI hack
Trending now
- Audi unveils 2027 Q9 full-size SUV flagship for US
- Mexican cartels outsource meth labs to Nigeria
- Kenya probes 15 elephant deaths in Amboseli park
- Meta's AI data center financing costs rise in $14 billion BlackRock deal
- Cyera acquires Oasis Security for $1B in third deal this year
- NASA Swift rescue mission hits attitude control trouble
- American Airlines grounds all flights nationwide after IT outage
- SK Hynix Q2 profit surges 557% to record high
Comments
No comments yet. Be the first.