WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
Published: 2026-07-20
CVE-2026-63030 and CVE-2026-60137 form the wp2shell pre-auth RCE chain in WordPress Core. Exploitation confirmed. Patches in WordPress 7.0.2 and 6.9.5.
https://latesthackingnews.com/2026/07/26/wp2shell-vulnerability-wordpress-rce/
https://www.securityweek.com/wp2shell-wordpress-vulnerabilities-exploited-in-the-wild/
https://www.infosecurity-magazine.com/news/researchers-wordpress-exploit/
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-fpp7-x2x2-2mjf
https://github.com/DeadExpl0it/wp2shell-poc
https://github.com/mhassani97/cve-2026-63030-lab
https://github.com/TranDongA3/POC-CVE-2026-63030-CVE-2026-60137-
https://github.com/g0d150ne/WP2Shell
https://github.com/M4xSec/wp2shell-Exploit-Waf-Bypass
https://github.com/AnggaTechI/CVE-2026-63030
https://github.com/AbdullahMaqbool22/CVE-2026-60137-WordPress-Core-SQL-Injection-PoC
https://github.com/rechandra/wp2exp-2026
https://github.com/AdarshThakur14777-cyber/CVE-2026-60137
https://github.com/johnlodan/wp2shell-rce
https://github.com/michael-kanda/Wp2shell-ioc-scanner
https://github.com/BytesPulse-OE/wp2shell-Hestia-Scanner
https://github.com/yuag/wp2shell
https://github.com/Dungsocool/CVE-2026-60137_CVE-2026-63030
https://github.com/northsia/CVE-2026-60137-With-Skip-SSL
https://github.com/shinthink/CVE-2026-63030
https://github.com/Giangdurian/CVE-2026-63030-CVE-2026-60137
https://github.com/razureink/cve-2026-63030_60137-wordpress_rce_reproduction
https://github.com/gagaltotal/CVE-2026-63030-CVE-2026-60137-wp2shell-poc
https://github.com/raphy76/wp2shell-poc-fulljs
https://github.com/Adrees-Basheer/wp2shell-vulnerability-scanner
https://github.com/mcipekci/wp2shell
https://github.com/Bhanunamikaze/WP2Shell-CVE-2026-63030-POC
https://github.com/Colere-Sys/wp2shell-poc
https://github.com/mrmtwoj/Fix-CVE-2026-60137-CVE-2026-63030-in-wordpress
https://github.com/ChPratik/Threat_intelligence_Portfolio
https://github.com/lucifer0xf/wp2shell-Wordpress-TOWN
https://github.com/GhostInExile/CVE-2026-63030-Wp2Shell
https://github.com/SentinelXofficial/sxwp2shell
https://github.com/0xjessie21/wp2shell-checker
https://github.com/joaovicdev/EXPLOIT-CVE-2026-63030
https://github.com/Crypto-Cat/wp2shell
https://github.com/ZenithGenius/wordpress-batch-rce-lab
https://github.com/vulnquest58/PressVector
https://github.com/skelersecurity/wordpress-skelersecurity-core-security-CVE-2026-63030
https://github.com/Lukols-Dev/wp-cve-2026-63030-check
https://github.com/ananay/wp2shell-lab
https://github.com/hidden-investigations/wp2shell-scanner
https://github.com/4B3R4M4-607D/CVE-2026-63030-POC
https://github.com/0xh7ml/CVE-2026-63030
https://github.com/eyesecurity/wp2shell-compromise-scanner-plugin
https://github.com/bahartanir/wp2shell-scanner
https://github.com/ikow/wp2shell
https://github.com/c0gnit00/Wp2Shell
https://github.com/edenzaraf/wp2shell
https://github.com/codeb0ssx/Ultimate-wp2shell
https://github.com/JohenLastGen-JLG/wp2shell
https://github.com/own2pwn-fr/wp2shell-detect
https://github.com/securelayer7/WordPresShell
https://github.com/ebrasha/abdal-cve-2026-63030
https://github.com/ebrasha/abdal-cve-2026-60137
https://github.com/yoerivegt/wp2shell-poc
https://github.com/zi3lak/wp2shell_scanner
https://github.com/0xWhoknows/wp2shell
https://github.com/mrx-arafat/CVE-2026-63030-POC
https://github.com/h4cd0c/wp2shell
https://github.com/0xBlackash/CVE-2026-63030
https://github.com/0xsha/wp2shell
https://github.com/mverschu/CVE-2026-63030
https://github.com/4minx/CVE-2026-63030
https://github.com/kulichr/wp2shell
https://github.com/NULL200OK/WP2Shell
https://github.com/ekomsSavior/wp2shell
https://github.com/47Cid/wp2shell-lab
https://github.com/dinosn/wp2shell-lab
https://github.com/tcyph3r/wp2shell-cve-2026-63030-root-cause
https://github.com/Senanfurkan/wordpress-cve-2026-63030
https://github.com/ZephrFish/wp2shell-scanner
https://github.com/Icex0/wp2shell-poc
https://github.com/nando0x0a/ThreatForge
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-60137
Published: 2026-07-17
Updated: 2026-07-29
Named Vulnerability: wp2shellKnown Exploited Vulnerability (KEV)
Base Score: 5.4
Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:N/A:N
Severity: Medium
Base Score: 9.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity: Critical
EPSS: 0.78305
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest