Critical WordPress RCE Vulnerability 'wp2shell' Gets Public Exploits, Patch Urged

A critical WordPress Core flaw lets unauthenticated attackers run arbitrary code — and public exploits are now available.

A critical remote code execution vulnerability in WordPress Core, tracked as CVE-2026-63030 and nicknamed 'wp2shell,' can be exploited by anyone without logging in or requiring special plugins or configurations. The flaw is classified as pre-authentication RCE, meaning an attacker needs no foothold on a site before triggering it. Public exploit code has since been released, sharply raising the risk for unpatched installations. WordPress powers a large share of websites globally, making the potential attack surface for this vulnerability exceptionally wide. Security vendors including Imperva have confirmed protections for their customers, and BleepingComputer has urged administrators to patch immediately.

Why it matters

Because WordPress underlies a substantial portion of the web and this flaw requires no authentication, millions of sites could be compromised with automated attacks using the now-public exploit code.

What's next

Site administrators are advised to apply the WordPress Core patch immediately; watch for further exploit activity as public proof-of-concept code circulates.

Key facts

Bias & framing notes

Source 1 (IT Security News via Imperva) frames the story around customer protection, emphasizing Imperva's defensive posture rather than the broader threat. Source 2 (BleepingComputer) focuses on the availability of public exploits and the urgency to patch, which is a more user-actionable angle. Neither source provided full technical details in the excerpts available, limiting verification of specifics such as affected version ranges.

NewsClear — neutral news & congressional tracking · Bill of the Week