Post by The Hacker News

720,736 followers

⚡ UPDATE: #wp2shell now has two CVEs, and a working proof-of-concept is public. > CVE-2026-63030 breaks REST batch routing > CVE-2026-60137 injects SQL Chained, they give an anonymous attacker code execution on affected WordPress sites. How the exploit path works: https://lnkd.in/gnUhEQGE

Post content