WordPress developers have released a security update to fix the vulnerabilities
The vulnerabilities have been dubbed WP2Shell and they are officially tracked as CVE-2026-60137 and CVE-2026-63030. CVE-2026-60137 is a high-severity SQL injection bug and CVE-2026-63030 is a critical arbitrary code execution vulnerability. Chaining the two flaws enables an attacker to achieve unauthenticated remote code execution on affected WordPress websites.
WordPress announced patches with the release of versions 7.0.2, 6.9.5 and 6.8.6 - wordpress.org.
Source: securityweek.com
22 July 2026