New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
A critical remote code execution flaw dubbed 'wp2shell' allows unauthenticated attackers to run code within WordPress Core via SQL injection.
📍 The outcome
The wp2shell vulnerability was identified as a critical remote code execution flaw in WordPress Core caused by SQL injection. Security providers like Cloudflare and Imperva offered protection against the pre-authentication vulnerability.
Aikido Security advised users to patch the flaw immediately.
Epilogue added 42d ago, after coverage quieted.
Answered
What is wp2shell?
It is a critical pre-authentication remote code execution (RCE) vulnerability in WordPress Core, tracked as CVE-2026-63030.
How does the attack work?
According to Aikido Security, the vulnerability is executed via SQL injection, allowing unauthenticated attackers to run code.
Are there protections available?
Cloudflare and Imperva have reported that their protection services and WAFs are defending against the flaw.
Where it stands
A vulnerability identified as CVE-2026-63030, known as wp2shell, has been discovered in WordPress Core. The flaw is a pre-authentication remote code execution (RCE) vulnerability that leverages SQL injection, potentially allowing attackers to gain full control over affected websites.
Coverage from The Hacker News, Rapid7, and Aikido Security emphasizes the critical nature of the flaw. Security providers including Imperva and Cloudflare have stated that their respective WAF and protection services are guarding applications against this vulnerability.
Users are advised to patch the vulnerability immediately. Coverage does not yet specify the exact version of WordPress affected or the specific timeline for the patch release.
Synthesized by Newsylist from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 42d ago.
Who reported it (8)
- Imperva Customers Protected Against “wp2shell” Pre-Authentication RCE in WordPress Core Security Boulevard · 45d ago
- wp2shell: A Pre-Authentication RCE in WordPress Core, and Why It Is an Exposure Validation Problem Security Boulevard · 45d ago
- Aikido Security Highlights WordPress Vulnerability and Positions Runtime Protection Offering TipRanks · 45d ago
- Critical Wordpress Plugin Vulnerability Allows Attackers to Gain Full Control Over Website CyberSecurityNews · 45d ago
- CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core Rapid7 · 45d ago
- Unauthenticated RCE Vulnerability in WordPress core (wp2shell), via SQL injection. Patch the vulnerability now! Aikido Security · 45d ago
- Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities The Cloudflare Blog · 45d ago
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code The Hacker News · 45d ago broke it first
Momentum
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
People, places & organizations
Topics
Related trends
White House AI Guidelines Exempt U.S. Open Models From Government Review
The White House prepares a new framework for artificial intelligence security reviews with exemptions for open models.
Ariana Grande Sues Over Yearslong Hacking Campaign Targeting Inner Circle
Ariana Grande has filed a lawsuit against alleged hackers following a yearslong campaign targeting her inner circle and leaking unreleased music.
Microsoft launches its first cybersecurity model, plus a new agentic cybersecurity system
Microsoft is challenging industry leaders with a new in-house cybersecurity AI model and an agentic system designed to lower costs.
Microsoft Unveils A.I. Cybersecurity Tools
Microsoft is entering the "agentic era" of security with the launch of its first homegrown AI model and new cybersecurity tools.
Angelina Jolie and Robert De Niro at centre of contact detail ‘leak’
A data breach at the Tribeca Film Festival has resulted in the exposure of private contact information for high-profile Hollywood figures.
Claude Cowork escaped sandbox on Mac, gain full access to all files
Security experts have identified a vulnerability allowing the Claude Cowork AI agent to bypass virtual machine isolation and access local files on Mac systems.