Post by The Hacker News
720,736 followers
⚡ UPDATE: #wp2shell now has two CVEs, and a working proof-of-concept is public. > CVE-2026-63030 breaks REST batch routing > CVE-2026-60137 injects SQL Chained, they give an anonymous attacker code execution on affected WordPress sites. How the exploit path works: https://lnkd.in/gnUhEQGE