Critical WordPress RCE Vulnerability 'wp2shell' Gets Public Exploits, Patch Urged
A critical WordPress Core flaw lets unauthenticated attackers run arbitrary code — and public exploits are now available.
A critical remote code execution vulnerability in WordPress Core, tracked as CVE-2026-63030 and nicknamed 'wp2shell,' can be exploited by anyone without logging in or requiring special plugins or configurations. The flaw is classified as pre-authentication RCE, meaning an attacker needs no foothold on a site before triggering it. Public exploit code has since been released, sharply raising the risk for unpatched installations. WordPress powers a large share of websites globally, making the potential attack surface for this vulnerability exceptionally wide. Security vendors including Imperva have confirmed protections for their customers, and BleepingComputer has urged administrators to patch immediately.
Why it matters
Because WordPress underlies a substantial portion of the web and this flaw requires no authentication, millions of sites could be compromised with automated attacks using the now-public exploit code.
What's next
Site administrators are advised to apply the WordPress Core patch immediately; watch for further exploit activity as public proof-of-concept code circulates.
Key facts
- Vulnerability is tracked as CVE-2026-63030, nicknamed 'wp2shell'
- Classified as pre-authentication RCE — no login or special configuration required to exploit
- Public exploit code has been released, increasing active exploitation risk
- Affects WordPress Core itself, not a third-party plugin or theme
- Security firm Imperva has deployed protections for its customers
- BleepingComputer is urging administrators to patch now
Bias & framing notes
Source 1 (IT Security News via Imperva) frames the story around customer protection, emphasizing Imperva's defensive posture rather than the broader threat. Source 2 (BleepingComputer) focuses on the availability of public exploits and the urgency to patch, which is a more user-actionable angle. Neither source provided full technical details in the excerpts available, limiting verification of specifics such as affected version ranges.
NewsClear — neutral news & congressional tracking · Bill of the Week