WordPress CVE-2026-63030: Critical RCE in Core Demands Immediate Patching
A critical remote code execution (RCE) vulnerability designated CVE-2026-63030, dubbed “wp2shell,” has been discovered in WordPress Core affecting versions 6.4 through 6.7.1. The flaw allows unauthenticated attackers to execute arbitrary PHP code on vulnerable servers through malicious HTTP requests