Critical security vulnerability in WordPress Core (wp2shell)

Incident Report for raidboxes®

Resolved

All security updates were rolled out on all Boxes as planned yesterday evening by 8 PM.
_____
Alle Sicherheitsupdates sind wie geplant gestern Abend bis 20 Uhr auf allen Boxen aufgespielt worden.
Posted Jul 19, 2026 - 07:30 CEST

Monitoring

Security researchers have found two vulnerabilities in WordPress core that can be chained into an exploit, allowing code to be injected without prior authentication.
Specifically, it involves a critical SQL injection (CVE-2026-60137, CVSS 9.1) combined with a flaw in the REST API (wp2shell, CVE-2026-63030, CVSS 7.5). WordPress 6.9 and 7.0 are affected, with the SQL injection also affecting WordPress 6.8. We are not aware of any active exploitation at this time.

We'll roll out the security updates on all Boxes today – this process will be completed by the end of the day.

____________

Sicherheitsforscher haben zwei Sicherheitslücken in WordPress Core gefunden, die sich zu einem Exploit verketten lassen und dann das Einschleusen von Schadcode ohne vorherige Anmeldung ermöglichen. Betroffen ist bereits die reine Standard-Installation, ohne zusätzliche Plugins.
Im Detail handelt es sich um eine kritische SQL-Injection (CVE-2026-60137, CVSS 9,1) in Verbindung mit einem Fehler im REST-API (wp2shell, CVE-2026-63030, CVSS 7,5). Betroffen sind WordPress 6.9 und 7.0, die SQL-Injection zusätzlich WordPress 6.8. Das WordPress-Team hat die Sicherheitsreleases 6.8.6, 6.9.5 und 7.0.2 veröffentlicht. Aktive Angriffe sind uns zum aktuellen Zeitpunkt nicht bekannt.

Wir werden die Sicherheitsupdates noch heute auf allen Boxen ausrollen – dieser Prozess wird zum Ende des Tages erledigt sein.
Posted Jul 18, 2026 - 09:09 CEST