WP2Shell: WordPress Core SQLi + REST API Chain to Pre-Auth RCE
A newly disclosed WordPress exploit chain, nicknamed “WP2Shell,” lets unauthenticated attackers achieve remote code execution (RCE) on any WordPress Core installation, no plugins required. Disclosed on July 17, 2026, the chain combines two vulnerabilities: CVE-2026-60137 (SQL injection) and CVE-2026-63030 (REST API batch-route confusion).