Public exploits are available for the WordPress “wp2shell” chain.
Working proof-of-concept code has been released for two WordPress Core vulnerabilities that can be chained to execute code without authentication. CVE-2026-63030 involves confusion in the REST API batch-routing mechanism, while CVE-2026-60137 is an SQL-injection vulnerability. The combination can turn a single anonymous HTTP request into remote code execution under certain configurations, including sites using persistent object caching. WordPress addressed the problems in versions 6.9.5 and 7.0.2 and initiated forced automatic updates. The availability of public exploit code substantially increases the risk to sites where automatic updating failed or was disabled.