# wp2shell

> **TL;DR.** wp2shell is the nickname for [CVE-2026-63030](https://wp2shell.

- **Category:** Cybersecurity / Vulnerabilities / WordPress
- **Stage:** emergent
- **Age:** 9 days
- **Origin date:** 2026-07-17
- **First detected:** 2026-07-19
- **Canonical URL:** https://earlyterms.com/term/wp2shell
- **Sources:** 6 primary URLs

## Definition

wp2shell is the nickname for [CVE-2026-63030](https://wp2shell.com/), a WordPress Core exploit chain that lets an anonymous attacker run arbitrary code on a stock install with no plugins and no account. It pairs a REST API batch-route confusion bug with a separate SQL injection, CVE-2026-60137, in `WP_Query`.

Searchlight Cyber researcher Adam Kues disclosed the chain on July 17, 2026, the same day WordPress shipped patches 6.9.5 and 7.0.2 for the affected 6.9.0-6.9.4 and 7.0.0-7.0.1 branches, with wordpress.org forcing automatic updates given the severity. Public proof-of-concept exploits reached GitHub within hours, and watchTowr reported early in-the-wild exploitation days later.

## Analogy

A skeleton key smuggled in through the site's own front-desk delivery hatch — no login, no ID, no plugin required.

## Why it's emerging now

WordPress patched wp2shell (CVE-2026-63030 chained with CVE-2026-60137) on July 17, 2026, forcing auto-updates to 6.9.5 and 7.0.2 after Searchlight Cyber's Adam Kues found a way for anonymous attackers to run code on any stock install; within a day, five public PoC repos hit GitHub and watchTowr flagged early in-the-wild exploitation.

## Related terms

- *parent:* WordPress
- *related:* CVE-2026-60137
- *parent:* pre-auth RCE
- *related:* REST API batch route confusion
- *related:* SQL injection
- *related:* Log4Shell
- *related:* ProxyShell
- *related:* proof-of-concept exploit
- *related:* web application firewall
- *parent:* zero-day vulnerability

## Sources

1. [Searchlight Cyber — wp2shell writeup](https://wp2shell.com/)
2. [The Hacker News — wp2shell coverage](https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html)
3. [BleepingComputer — public exploits, patch now](https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/)
4. [Icex0/wp2shell-poc — full RCE chain repo](https://github.com/Icex0/wp2shell-poc)
5. [Hacker News — Pre-Authentication RCE in WordPress Core (22 pts)](https://news.ycombinator.com/item?id=48951744)
6. [SecurityWeek — WP2Shell exploited in the wild](https://www.securityweek.com/wp2shell-wordpress-vulnerabilities-exploited-in-the-wild/)

---
_Generated by EarlyTerms · https://earlyterms.com/term/wp2shell_
