PULSE the living trend engine
◼ Archived Technology 🔮 PULSE predicts: still trending tomorrow

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

A critical pre-authentication remote code execution vulnerability known as wp2shell allows unauthenticated attackers to run code in WordPress Core.

8sources
9articles
6velocity
+0%since first seen
45d agofirst detected

🌍 Cross-language spread

This story first appeared in 🇩🇪 German coverage — 2.7 hours before PULSE detected it in English news.

🇬🇧 English Jul 18, 04:07 UTC
🇩🇪 German Jul 18, 01:27 UTC · it boltwise

Detected by matching proper nouns and figures that survive translation. Times reflect when each edition's coverage was first indexed.

Velocity

How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →

📍 How it ended

The wp2shell vulnerability was identified as a critical pre-authentication remote code execution flaw in WordPress Core caused by SQL injection. Security providers like Imperva and Cloudflare implemented protections against the exploit, while others urged users to patch the vulnerability.

Epilogue added 28d ago, after coverage quieted.

The brief

A critical security flaw identified as wp2shell has been discovered within the WordPress Core. This vulnerability, cataloged as CVE-2026-63030, is a remote code execution (RCE) flaw that enables unauthenticated attackers to run code on affected systems. According to Aikido Security, the vulnerability is facilitated via SQL injection. The flaw is described as pre-authentication, meaning that an attacker does not need valid login credentials to execute the exploit and potentially gain full control over the targeted website. Major security outlets and service providers are actively reporting on the risk and their corresponding defenses. The Hacker News and cyberkendra.com have highlighted that the flaw lets anyone run code, while Rapid7 specifically identifies the vulnerability by its CVE-2026-63030 designation.

Security Boulevard provides analysis on the issue, framing wp2shell as an exposure validation problem. Meanwhile, CyberSecurityNews reports that the vulnerability allows attackers to gain complete control over the impacted websites, stressing the severity of the exploit. Contextually, this vulnerability represents a high-severity risk due to its location in the core software rather than a third-party plugin, although CyberSecurityNews mentions a plugin vulnerability in its reporting. The urgency of the situation is underscored by Aikido Security, which has issued a direct call for users to patch the vulnerability immediately. The scale of the threat has prompted several cloud and security infrastructure providers to implement protective measures to shield WordPress applications from the exploit before users can apply manual patches. Immediate attention is being directed toward runtime protection and web application firewall (WAF) updates.

The Cloudflare Blog reports that the Cloudflare WAF is protecting WordPress applications from two high-severity vulnerabilities, including this one. Imperva has stated that its customers are protected against the wp2shell pre-authentication RCE. Additionally, TipRanks notes that Aikido Security is utilizing this vulnerability to position its runtime protection offerings. Users are advised to monitor for official patches and maintain their WAF configurations to mitigate the risk of unauthorized code execution.

Synthesized by PULSE from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 37d ago.

Quick answers

What is wp2shell?

wp2shell is a critical pre-authentication remote code execution (RCE) vulnerability in WordPress Core, identified as CVE-2026-63030.

How is the wp2shell vulnerability exploited?

According to Aikido Security, the vulnerability is executed via SQL injection, allowing unauthenticated attackers to run code.

Which services provide protection against this flaw?

Cloudflare WAF and Imperva both report providing protection for WordPress applications against this vulnerability.

Coverage (9)

Topics

Related trends

▲ Peaking Business 🔮 fades

AI critic predicts doomsday within a decade

Concerns over artificial intelligence mount as a critic predicts a doomsday scenario within ten years amidst debates on security and encryption.

5 sources 5 articles v 3 1d ago