https://reddit.com/r/netsec/comments/1v0kvve/wp2shell_cve202663030_update_public_working/: wp2shell (CVE-2026-63030) update: public working exploit now available for the WordPress core pre-auth RCE
Published Jul 19, 2026
·Updated
Affected Software
2 affected components
WordPress WordPress>=6.9.0<=6.9.4, >=7.0.0<=7.0.1
WordPress WordPress>6.8.6<7.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-63030?
CVE-2026-63030 has been classified as a critical vulnerability due to its ability to enable pre-authentication remote code execution in the WordPress core.
2
How do I fix CVE-2026-63030?
To mitigate CVE-2026-63030, update your WordPress installation to the latest version that includes the patch for this vulnerability.
3
What systems are affected by CVE-2026-63030?
CVE-2026-63030 affects the WordPress core across various versions prior to the release of the patch.
4
What are the potential impacts of CVE-2026-63030?
Exploitation of CVE-2026-63030 can lead to full server compromise and unauthorized remote access to the affected WordPress site.
5
Is there a public exploit available for CVE-2026-63030?
Yes, a public working exploit for CVE-2026-63030 has been released and is available on GitHub.