Holy shit
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
" Independent proof-of-concept for the unauthenticated WordPress REST batch route-confusion SQL injection associated with Searchlight Cyber's wp2shell advisory."
GitHub - Icex0/wp2shell-poc: wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain
wp2shell (CVE-2026-63030 & CVE-2026-60137) - full RCE chain - Icex0/wp2shell-pocGitHub

Milo
in reply to stux⚡️ • • •Ray McCarthy
in reply to Milo • • •Using the Internet is a security risk. Server or client.
Milo
in reply to Ray McCarthy • • •stux⚡️
in reply to Milo • • •Ray McCarthy
in reply to stux⚡️ • • •@milo
People need to not madly add plugins, which increase the vulnerability, assuming not actually malware.
Some other CMS are dreadful to update. Especial Drupal or Mediawiki. So people don't update!
Adobe Commerce used to be Magneto and was terrible for vulnerabilities?
Wordpress suffers from the exposure of being the most popular? Your own install with custom .htaccess and file permissions (especially on upload directories).
Alda Vigdís
in reply to stux⚡️ • • •Lauren Weinstein
in reply to stux⚡️ • • •Laura
in reply to stux⚡️ • • •