Public exploits are now available for two critical WordPress flaws that attackers can chain to gain remote code execution without authentication. Public proof-of-concept exploits are now available for the critical wp2shell vulnerabilities affecting WordPress Core. The flaws, tracked as CVE-2026-63030 and CVE-2026-60137, can be chained to achieve pre-authentication remote code execution on default

Public exploits are now available for a pair of critical vulnerabilities in WordPress Core, which, when chained, allow attackers to achieve pre-authentication remote code execution on affected installations. The flaws, collectively dubbed "wp2shell," impact WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.
The vulnerabilities are tracked as CVE-2026-63030 and CVE-2026-60137. CVE-2026-63030 is a REST API batch-route confusion bug that was introduced in WordPress 6.9. CVE-2026-60137 is a high-severity SQL injection flaw found in the `author__not_in` parameter of `WP_Query`.
Cybersecurity researchers at Searchlight Cyber discovered these flaws, noting that they can be exploited by an anonymous user on a default WordPress installation without any plugins. This makes immediate patching crucial for the estimated 500 million websites that utilize WordPress.
WordPress has confirmed the issues and released security updates. The company's 7.0.2 security release addresses one critical and one high-severity security issue. Due to the severity of these vulnerabilities, the WordPress.org team has enabled forced updates via its auto-update system for sites running the affected versions.
Site owners are strongly advised to update immediately to WordPress 7.0.2 or 6.9.5, as these versions prevent the exploitation of the wp2shell attack chain.
For administrators unable to patch immediately, temporary mitigation strategies include blocking anonymous access to the REST API batch endpoint. This can be achieved through a security plugin or by implementing Web Application Firewall (WAF) rules targeting `/wp-json/batch/v1` and `?rest_route=/batch/v1`. However, Searchlight Cyber emphasizes that these are only temporary measures and may impact legitimate site functions, making a full update the preferred and most secure solution.
Researchers initially withheld technical details of the exploits to provide organizations with time to patch. They have since released an online tool to assist administrators in checking whether their WordPress instances are vulnerable.

Anthropic pointed Claude Mythos Preview at 281 open-source projects and collected 23,019 candidate vulnerabilities. External security firms reviewed 1,900 of them. Maintainers received 1,596 reports and acknowledged 1,451; 97 fixes landed upstream, and 88 findings became published security advisories, with counts current as of May 22, 2026. The other 21,119 candidates have not been reviewed by any

Here’s a look at the most interesting products from the past week, featuring releases from BugBase, F5 Networks, Ping Identity, and Superna. F5 speeds up virtual patching to counter AI-driven threats With new features such as anomaly detection and agentic threat intelligence, F5’s AI-powered web application firewall (WAF) is capable in delivering real-time protections because of its strategic posi

Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix

SonicWall customers have confronted a barrage of attacks for years, including five actively exploited vulnerabilities in SMA 1000 appliances since late 2025. The post Attackers exploit zero-days in consistently besieged SonicWall product appeared first on CyberScoop.

