WordPress core pre-auth RCE patch bundle (6.9.5, 7.0.2)
Security Patch Release
Summary
Hide ▲
Show ▼
WordPress Core patched a pre-auth RCE on July 17, 2026 with 6.9.5 and 7.0.2, and the release also enabled forced automatic updates for supported installations. The vulnerability can be triggered by an anonymous request on a default install with no plugins, covering 6.9.0-6.9.4 and 7.0.0-7.0.1. Researchers later linked the broader wp2shell chain to CVE-2026-63030 and CVE-2026-60137, and confirmed active exploitation against WordPress Core after the fix. Observed abuse included probing, SQL injection attempts, malicious plugin uploads, and PHP webshell deployment on affected servers.
Related Happenings
ServiceNow security patch release for CVE-2026-6875
Security Patch Release
H score47
First: 20.07.2026 12:29
Last: 20.07.2026 12:29
Sources 1
About this happening:
ServiceNow released CVE-2026-6875 security updates for the ServiceNow AI Platform, covering hosted and self-hosted instances. The patch addresses a pre-auth sand...
ServiceNow security patch release for CVE-2026-6875
Security Patch ReleaseAbout this happening: ServiceNow released CVE-2026-6875 security updates for the ServiceNow AI Platform, covering hosted and self-hosted instances. The patch addresses a pre-auth sand...
SimpleHelp security update for CVE-2026-48558
Security Patch Release
H score65
First: 15.06.2026 23:06
Last: 15.06.2026 23:06
Sources 1
About this happening:
SimpleHelp released 5.5.16 and 6.0 RC2 on June 9 to fix CVE-2026-48558, a critical OIDC authentication flaw in SimpleHelp remote management software th...
SimpleHelp security update for CVE-2026-48558
Security Patch ReleaseAbout this happening: SimpleHelp released 5.5.16 and 6.0 RC2 on June 9 to fix CVE-2026-48558, a critical OIDC authentication flaw in SimpleHelp remote management software th...
The vendor security patch release for CVE-2026-8206
Security Patch Release
H score89
First: 03.06.2026 01:12
Last: 03.06.2026 01:12
Sources 1
About this happening:
Kirki - Freeform Page Builder, Website Builder & Customizer shipped version 6.0.7 to fix CVE-2026-8206, a privilege-escalation flaw that could let attackers take over...
The vendor security patch release for CVE-2026-8206
Security Patch ReleaseAbout this happening: Kirki - Freeform Page Builder, Website Builder & Customizer shipped version 6.0.7 to fix CVE-2026-8206, a privilege-escalation flaw that could let attackers take over...
WP Maps Pro 6.1.1 security patch for CVE-2026-8732
Security Patch Release
H score49
First: 31.05.2026 17:06
Last: 31.05.2026 17:06
Sources 1
About this happening:
WP Maps Pro 6.1.1 was released to fix CVE-2026-8732, giving WordPress administrators a patch for a flaw that enabled unauthenticated administrator-account creation. Th...
WP Maps Pro 6.1.1 security patch for CVE-2026-8732
Security Patch ReleaseAbout this happening: WP Maps Pro 6.1.1 was released to fix CVE-2026-8732, giving WordPress administrators a patch for a flaw that enabled unauthenticated administrator-account creation. Th...
CPanel and WHM emergency update for critical auth-bypass
Security Patch Release
H score89
First: 29.04.2026 18:51
Last: 29.04.2026 18:51
Sources 1
About this happening:
WebPros International released an emergency update for cPanel and WHM after a critical authentication-bypass flaw could expose supported installations to una...
CPanel and WHM emergency update for critical auth-bypass
Security Patch ReleaseAbout this happening: WebPros International released an emergency update for cPanel and WHM after a critical authentication-bypass flaw could expose supported installations to una...
Timeline
-
21.07.2026 19:41 1 articles · 10d ago
WordPress sites face wp2shell probing and SQL injection attempts
Exploitation ObservedWordPress sites saw wp2shell probing at 23:29 UTC on July 17, followed 13 minutes later by a clear SQL injection attempt; Wiz also described attacks that mass-scanned vulnerable installations, abused plugin upload functionality, installed PHP webshells, and targeted wp-config through admin-ajax.php.
Show sources
- Critical wp2shell WordPress flaws exploited to install webshells — www.bleepingcomputer.com — 21.07.2026 19:41
-
18.07.2026 00:20 1 articles · 13d ago
Adam Kues reports a WordPress core pre-auth RCE
Initial DisclosureAdam Kues at Assetnote, Searchlight Cyber's attack surface management arm, reported a WordPress core flaw through WordPress's HackerOne program; the wp2shell writeup says the issue has no preconditions and can be exploited by an anonymous user on a default install with no plugins.
Show sources
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code — thehackernews.com — 18.07.2026 00:20
-
18.07.2026 00:20 3 articles · 13d ago
WordPress ships 6.9.5 and 7.0.2 to close the anonymous RCE
Mitigation Patch UpdateWordPress released 6.9.5 and 7.0.2 on July 17, 2026, closing a pre-auth RCE in WordPress core that an anonymous request can trigger against a default install with no plugins; the release also enabled forced updates through the auto-update system, covering 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.
Show sources
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code — thehackernews.com — 18.07.2026 00:20
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code — thehackernews.com — 18.07.2026 00:20
- Researchers Build WordPress Exploit Using OpenAI's GPT — www.infosecurity-magazine.com — 20.07.2026 17:00