Find notable cyber news and cases, enriched with sources, timelines, and signals.

WordPress core pre-auth RCE patch bundle (6.9.5, 7.0.2)

Security Patch Release
First reported
Last updated
Happening score
H score 66
3 unique sources, 3 articles

Summary

Hide ▲

WordPress Core patched a pre-auth RCE on July 17, 2026 with 6.9.5 and 7.0.2, and the release also enabled forced automatic updates for supported installations. The vulnerability can be triggered by an anonymous request on a default install with no plugins, covering 6.9.0-6.9.4 and 7.0.0-7.0.1. Researchers later linked the broader wp2shell chain to CVE-2026-63030 and CVE-2026-60137, and confirmed active exploitation against WordPress Core after the fix. Observed abuse included probing, SQL injection attempts, malicious plugin uploads, and PHP webshell deployment on affected servers.

Related Happenings

ServiceNow security patch release for CVE-2026-6875

Security Patch Release
H score47 First: 20.07.2026 12:29 Last: 20.07.2026 12:29 Sources 1

About this happening: ServiceNow released CVE-2026-6875 security updates for the ServiceNow AI Platform, covering hosted and self-hosted instances. The patch addresses a pre-auth sand...

SimpleHelp security update for CVE-2026-48558

Security Patch Release
H score65 First: 15.06.2026 23:06 Last: 15.06.2026 23:06 Sources 1

About this happening: SimpleHelp released 5.5.16 and 6.0 RC2 on June 9 to fix CVE-2026-48558, a critical OIDC authentication flaw in SimpleHelp remote management software th...

The vendor security patch release for CVE-2026-8206

Security Patch Release
H score89 First: 03.06.2026 01:12 Last: 03.06.2026 01:12 Sources 1

About this happening: Kirki - Freeform Page Builder, Website Builder & Customizer shipped version 6.0.7 to fix CVE-2026-8206, a privilege-escalation flaw that could let attackers take over...

WP Maps Pro 6.1.1 security patch for CVE-2026-8732

Security Patch Release
H score49 First: 31.05.2026 17:06 Last: 31.05.2026 17:06 Sources 1

About this happening: WP Maps Pro 6.1.1 was released to fix CVE-2026-8732, giving WordPress administrators a patch for a flaw that enabled unauthenticated administrator-account creation. Th...

CPanel and WHM emergency update for critical auth-bypass

Security Patch Release
H score89 First: 29.04.2026 18:51 Last: 29.04.2026 18:51 Sources 1

About this happening: WebPros International released an emergency update for cPanel and WHM after a critical authentication-bypass flaw could expose supported installations to una...

Timeline

  1. 21.07.2026 19:41 1 articles · 10d ago

    WordPress sites face wp2shell probing and SQL injection attempts

    Exploitation Observed

    WordPress sites saw wp2shell probing at 23:29 UTC on July 17, followed 13 minutes later by a clear SQL injection attempt; Wiz also described attacks that mass-scanned vulnerable installations, abused plugin upload functionality, installed PHP webshells, and targeted wp-config through admin-ajax.php.

    Show sources
  2. 18.07.2026 00:20 1 articles · 13d ago

    Adam Kues reports a WordPress core pre-auth RCE

    Initial Disclosure

    Adam Kues at Assetnote, Searchlight Cyber's attack surface management arm, reported a WordPress core flaw through WordPress's HackerOne program; the wp2shell writeup says the issue has no preconditions and can be exploited by an anonymous user on a default install with no plugins.

    Show sources
  3. 18.07.2026 00:20 3 articles · 13d ago

    WordPress ships 6.9.5 and 7.0.2 to close the anonymous RCE

    Mitigation Patch Update

    WordPress released 6.9.5 and 7.0.2 on July 17, 2026, closing a pre-auth RCE in WordPress core that an anonymous request can trigger against a default install with no plugins; the release also enabled forced updates through the auto-update system, covering 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.

    Show sources