headlinez.news Live news trend intelligence
◼ Archived Technology 🔮 headlinez.news predicts: fades by tomorrow — graded ✗ wrong

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

A critical remote code execution vulnerability, identified as wp2shell, has emerged in WordPress core, allowing unauthenticated access to websites.

7sources
8articles
5velocity
+0%since first seen
50d agofirst detected
Visual summary for New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
headlinez.news visual summary

📍 The outcome

The story of the wp2shell WordPress Core flaw quieted without a definitive conclusion in the coverage. The vulnerability was reported to allow unauthenticated attackers to run code, with multiple security companies highlighting the issue and urging users to patch it. Protection against the flaw was noted to be available to customers of certain security providers.

Epilogue added 47d ago, after coverage quieted.

Answered

What is wp2shell?

It is a critical pre-authentication remote code execution vulnerability found within WordPress core, identified as CVE-2026-63030.

How are attackers exploiting this flaw?

According to reports, the vulnerability is accessed via SQL injection, allowing unauthenticated attackers to run code.

Are there protections available?

Several security firms, such as Imperva, Aikido Security, and Cloudflare, report that their platforms are protecting customers from this vulnerability.

Where it stands

Security researchers have identified a pre-authentication remote code execution (RCE) flaw in WordPress core, designated as CVE-2026-63030. The vulnerability, referred to as wp2shell, allows unauthorized attackers to execute code and potentially gain full control over affected websites.

Coverage from The Hacker News, Rapid7, Security Boulevard, and Aikido Security emphasizes that the flaw is linked to SQL injection. Multiple security firms, including Imperva, Aikido Security, and Cloudflare, have reported that their respective protection offerings are being deployed to mitigate the vulnerability.

Future developments will depend on the release and adoption of official patches. Users are currently advised to utilize security protections to guard against potential exploitation until a core update is addressed.

Synthesized by headlinez.news from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 48d ago.

Who reported it (8)

Momentum

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

Topics

Related trends