Wire · founder news, decoded · technology
WordPress "wp2shell" exploit payload analyzed: AI developed this attack | Cybernews
◆ Published
22 July 2026
◆ Topic
technology
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 22 July 2026 · Fusion42 review
A critical WordPress vulnerability (CVE-2026-63030, dubbed 'wp2shell') was developed by AI (GPT-5.6 Sol) and is actively exploited in the wild; it requires only two HTTP POST requests to gain admin access via SQL injection through the REST API batch endpoint.
This Wire brief sits within Fusion42's coverage of Cybersecurity and Enterprise Software. Wire is Fusion42's founder-focused intelligence feed: each story is connected to the funds and startups it names — every one with a live profile on Raise or Scout — so founders can follow the capital and the momentum behind the headline rather than just the headline itself. Wire analysis is one of the live surfaces Arthur reasons over.
◆ The Wire takeaway
If you serve WordPress sites—hosting, plugins, security tooling, or management—your entire customer base is under active attack from an exploit that took AI 10 hours to write. The vulnerability is in WordPress core REST API, not third-party code; every unpatched instance is one HTTP request away from shell access.
◆ Related on Wire
- WordPress Core "wp2shell" RCE flaws get public exploits, patch now18 July 2026
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code18 July 2026
- New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released18 July 2026
- Patch now: WordPress REST API bug allows remote code execution20 July 2026
- Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk20 July 2026
- Attackers Exploit ServiceNow CVE-2026-6875 via Multiple Sandbox-Escape Routes20 July 2026
◆ Topics
Cybersecurity · Enterprise Software · wordpress-security · sql-injection · ai-weaponisation · rest-api-vulnerability · web-shell · critical-cve