Vulnerabilities
'wp2shell' WordPress Core Unauthenticated RCE Patched in 6.9.5 and 7.0.2 (CVE-2026-63030)
An unauthenticated remote-code-execution flaw in WordPress Core, disclosed as wp2shell, affects the 6.9 and 7.0 branches. Fixes shipped July 17 in 6.9.5 and 7.0.2 — defender teams and hosting providers should verify patch status rather than assume forced updates landed.