New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
A critical pre-authentication remote code execution vulnerability known as wp2shell allows unauthenticated attackers to run code in WordPress Core.
🌍 Cross-language spread
This story first appeared in 🇩🇪 German coverage — 2.7 hours before PULSE detected it in English news.
Detected by matching proper nouns and figures that survive translation. Times reflect when each edition's coverage was first indexed.
Velocity
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
📍 How it ended
The wp2shell vulnerability was identified as a critical pre-authentication remote code execution flaw in WordPress Core caused by SQL injection. Security providers like Imperva and Cloudflare implemented protections against the exploit, while others urged users to patch the vulnerability.
Epilogue added 28d ago, after coverage quieted.
The brief
A critical security flaw identified as wp2shell has been discovered within the WordPress Core. This vulnerability, cataloged as CVE-2026-63030, is a remote code execution (RCE) flaw that enables unauthenticated attackers to run code on affected systems. According to Aikido Security, the vulnerability is facilitated via SQL injection. The flaw is described as pre-authentication, meaning that an attacker does not need valid login credentials to execute the exploit and potentially gain full control over the targeted website. Major security outlets and service providers are actively reporting on the risk and their corresponding defenses. The Hacker News and cyberkendra.com have highlighted that the flaw lets anyone run code, while Rapid7 specifically identifies the vulnerability by its CVE-2026-63030 designation.
Security Boulevard provides analysis on the issue, framing wp2shell as an exposure validation problem. Meanwhile, CyberSecurityNews reports that the vulnerability allows attackers to gain complete control over the impacted websites, stressing the severity of the exploit. Contextually, this vulnerability represents a high-severity risk due to its location in the core software rather than a third-party plugin, although CyberSecurityNews mentions a plugin vulnerability in its reporting. The urgency of the situation is underscored by Aikido Security, which has issued a direct call for users to patch the vulnerability immediately. The scale of the threat has prompted several cloud and security infrastructure providers to implement protective measures to shield WordPress applications from the exploit before users can apply manual patches. Immediate attention is being directed toward runtime protection and web application firewall (WAF) updates.
The Cloudflare Blog reports that the Cloudflare WAF is protecting WordPress applications from two high-severity vulnerabilities, including this one. Imperva has stated that its customers are protected against the wp2shell pre-authentication RCE. Additionally, TipRanks notes that Aikido Security is utilizing this vulnerability to position its runtime protection offerings. Users are advised to monitor for official patches and maintain their WAF configurations to mitigate the risk of unauthorized code execution.
Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 37d ago.
Quick answers
What is wp2shell?
wp2shell is a critical pre-authentication remote code execution (RCE) vulnerability in WordPress Core, identified as CVE-2026-63030.
How is the wp2shell vulnerability exploited?
According to Aikido Security, the vulnerability is executed via SQL injection, allowing unauthenticated attackers to run code.
Which services provide protection against this flaw?
Cloudflare WAF and Imperva both report providing protection for WordPress applications against this vulnerability.
Coverage (9)
- Imperva Customers Protected Against “wp2shell” Pre-Authentication RCE in WordPress Core Security Boulevard · 46d ago
- wp2shell: A Pre-Authentication RCE in WordPress Core, and Why It Is an Exposure Validation Problem Security Boulevard · 46d ago
- Aikido Security Highlights WordPress Vulnerability and Positions Runtime Protection Offering TipRanks · 46d ago
- WP2Shell: Critical WordPress Flaw Lets Anyone Run Code cyberkendra.com · 46d ago
- Critical Wordpress Plugin Vulnerability Allows Attackers to Gain Full Control Over Website CyberSecurityNews · 46d ago
- CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core Rapid7 · 46d ago
- Unauthenticated RCE Vulnerability in WordPress core (wp2shell), via SQL injection. Patch the vulnerability now! Aikido Security · 46d ago
- Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities The Cloudflare Blog · 46d ago
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code The Hacker News · 46d ago
Topics
Related trends
Recently patched PaperCut zero-days used in data theft attacks
CISA adds PaperCut NG/MF vulnerabilities to its known exploited catalog as threat actors use zero-days for data theft.
Artificial intelligence agents going rogue fuel calls for regulation
Growing concerns over AI agents acting independently have sparked urgent debates regarding the efficacy of model rules as security measures.
Microsoft warns of TerminalFix attacks deploying reverse tunnels
Microsoft warns of TerminalFix attacks utilizing fake Cloudflare CAPTCHAs to establish reverse tunnels for unauthorized access.
AI Burnout Hits the People Charged With Defending Hospitals and Banks From Hackers
Cybersecurity professionals protecting hospitals and banks are facing burnout as AI-driven attacks accelerate in speed and scale.
Dwarkesh Patels’s wildly popular but dangerously misleading account of the OpenAI Hugging Face incident
A controversial narrative by Dwarkesh Patel regarding an OpenAI agent swarm hack of Hugging Face is facing scrutiny for being misleading.
AI critic predicts doomsday within a decade
Concerns over artificial intelligence mount as a critic predicts a doomsday scenario within ten years amidst debates on security and encryption.