# Urgent Patch Released for Dangerous WordPress Core Vulnerability

*Published July 20, 2026*
*Source: [https://cybersecuritynews.com/wp2shell-rce-vulnerability/](https://cybersecuritynews.com/wp2shell-rce-vulnerability/)*

## Executive Summary

A severe vulnerability named 'wp2shell' threatens millions of WordPress sites with remote code execution by unauthenticated attackers. WordPress.org has issued an urgent update to address the issue, and site owners are advised to apply patches immediately to protect their websites.

## Article

A critical vulnerability named 'wp2shell' has been identified in WordPress Core, posing a significant threat to over 500 million websites. Discovered by Adam Kues from Searchlight Cyber's Assetnote research team, this flaw allows remote code execution due to a REST API batch-route confusion issue. This issue leads to SQL injection and ultimately allows an unauthenticated attacker to take over websites without needing plugins or special configurations.

The vulnerability is particularly concerning because it requires no prior authentication. Attackers can exploit any WordPress site running an affected version as long as it is accessible online. To help site owners, Searchlight Cyber has withheld detailed exploit information and provided a free scanning tool at wp2shell.com to check for vulnerabilities.

The flaw affects specific versions of WordPress Core, identified by CVE-2026-60137 and CVE-2026-63030. While the WordPress 6.8 series is only affected by the SQL injection component, not the full RCE chain, a fix has been issued in version 6.8.6. WordPress.org responded swiftly by releasing version 7.0.2 and backported fixes in versions 6.9.5 and 6.8.6 to address both the RCE and SQL injection vulnerabilities. Due to the critical nature of the flaw, an automatic update has been pushed to all sites running the affected versions to ensure immediate protection.

Administrators can also manually update their sites via the WordPress Dashboard or by directly downloading the update from WordPress.org. For those unable to update right away, Searchlight Cyber suggests temporary measures, although these might affect normal site operations. Given the vast number of WordPress installations and the ease of exploiting this vulnerability, immediate patching is urged over relying on temporary solutions.
