Latest WordPress vulnerabilities: CVE-2026-60137 & CVE-2026-63030 #
WordPress disclosed multiple vulnerabilities affecting the core WordPress framework. The vulnerabilities have been designated CVE-2026-60137 and CVE-2026-63030, and are rated critical with a CVSS score of 9.8. These vulnerabilities have been dubbed wp2shell.
What is WordPress? #
Wordpress is a content management system that is designed for blog publishing and management of web content. It is widely deployed with a large set of plugins and is used for a wide variety of applications.
What is the impact? #
Successful exploitation of these issues may allow an unauthenticated remote attacker to conduct an SQL injection and gain remote administrative access and remote code execution on the vulnerable WordPress instances.
Are updates or workarounds available? #
Users are encouraged to update to the latest version as quickly as possible:
- 6.9.5 and later
- 7.0.2 and later
- 7.1 Beta 2 and late
How to find potentially vulnerable systems with runZero #
From the Services Inventory, use the following query to locate potentially impacted assets:
product:"wordpress" AND _service.product:wordpress