Black & White Path
Jul 19, 2026 · Information Security
Critical WordPress Core wp2shell Exploit Chain – Full Technical Analysis & POC
WordPress’s wp2shell vulnerability chain, disclosed by Adam Kues and Mustafa Can İpekçi, links CVE‑2026‑63030 REST route confusion with CVE‑2026‑60137 SQL injection to achieve pre‑authentication remote code execution via a single HTTP request, and the article details the exploit steps, detection scripts, and mitigation measures.
Privilege escalationRCEREST API
0 likes · 14 min read
