Wire · regulatory
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 18 July 2026 · Fusion42 review
Critical remote code execution flaws (CVE-2026-63030 and CVE-2026-60137) in WordPress Core versions 6.9.x and 7.0.x can be chained together for unauthenticated RCE; public exploits are now available and WordPress has enabled forced automatic updates.
This Wire brief sits within Fusion42's coverage of Cybersecurity, and 2 sources have reported it between 18 Jul 2026 and 22 Jul 2026.
◆ ◆ The Wire takeaway
If you build on WordPress — whether hosted SaaS, agency, or plugin — your entire customer base needs to patch in the next 48 hours or face remote takeover; this is the infrastructure event that forces you to move patch cycles to the top of your roadmap.
◆ Coverage
2 sources · first reported 18 Jul 2026 · latest 22 Jul 2026
◆ Related on Wire
◆ Topics