WordPress Core wp2shell RCE Flaws Get Public Exploits, Patch Now

Public exploits have been released for critical remote code execution vulnerabilities in WordPress Core dubbed wp2shell, making it imperative that administrators patch their sites immediately. The flaws, carrying CVE-2026-63030 among others, allow unauthenticated attackers to execute arbitrary code through WordPress REST API batch endpoints.

The vulnerability chain reportedly works by combining a SQL injection with an API bypass, allowing remote code execution on default WordPress installations without requiring additional plugins. Cloudflare confirmed that the vulnerable code path can be reached when a persistent object cache is not in use. WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected, with fixes in versions 6.9.5 and 7.0.2.

Rapid7, which tracked the disclosure, noted that while exploit details were initially withheld by the discoverer (Searchlight Cyber), public proof-of-concept code has since emerged, dramatically elevating the risk to unpatched sites. WordPress powers over 40% of websites globally, making this one of the most impactful vulnerabilities disclosed this year.

Administrators are urged to update immediately and review server logs for signs of attempted exploitation. CISA has not yet added the flaw to its KEV catalog, but security experts expect active scanning for vulnerable sites to begin imminently. As reported by Bleeping Computer and The Hacker News, this marks the most critical WordPress vulnerability in recent memory.