CVE Research
sekurity-team
InSEKurity of the Week (CW30/2026): WordPress Core wp2shell Pre-Auth RCE (CVE-2026-63030 & CVE-2026-60137)
A REST API batch-route confusion in WordPress Core chained with a WP_Query SQL injection gives unauthenticated attackers remote code execution on a default WordPress install -- no plugins, no credentials, and it is already being exploited in the wild.
Exploit
01