← Back

Wire · regulatory

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

Published

18 July 2026

Topic

regulatory

Sectors

Cybersecurity

Geography

United States

Source

Read at bleepingcomputer.com

Verified

Fusion42 · 18 July 2026 · Fusion42 review

Critical remote code execution flaws (CVE-2026-63030 and CVE-2026-60137) in WordPress Core versions 6.9.x and 7.0.x can be chained together for unauthenticated RCE; public exploits are now available and WordPress has enabled forced automatic updates.

This Wire brief sits within Fusion42's coverage of Cybersecurity, and 2 sources have reported it between 18 Jul 2026 and 22 Jul 2026.

◆ The Wire takeaway

If you build on WordPress — whether hosted SaaS, agency, or plugin — your entire customer base needs to patch in the next 48 hours or face remote takeover; this is the infrastructure event that forces you to move patch cycles to the top of your roadmap.

Coverage

2 sources · first reported 18 Jul 2026 · latest 22 Jul 2026

Related on Wire

Topics

Cybersecuritywordpress-rcecritical-patchsecurity-incidentrest-api-flawsql-injection