Skip to main content

Security Alert: Critical WordPress Update (wp2shell)

Date:
2026-07-24 08:16:00
Status:
Open
Brief Description:
wp2shell โ€” Cross-Platform RAT Deployment via Zero-Credential WordPress Exploit
Current Status:
N/A
Services Affected:
Custom Web and Application Development
Web Hosting
Full Description:
CVE-2026-63030 + CVE-2026-60137 ยท Pre-auth WordPress Core RCE chain used as initial access to deploy Agent-TCP, a cross-platform Go RAT, across Windows & Linux โ€” combined with mass IoT compromise across 14 CPU architectures, fileless execution via MemfdCreate, and DLL injection on Windows.

Affected: WordPress 6.9.0โ€“7.0.1. Fixed: 7.0.2 / 6.9.5. It is recommended that you update your sites immediately: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/

References:
https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
https://blog.offensive-intel.com/cross-platform-rat-deployment-via-wp2shell/#wordpress
CIT TDX ID: