NÚKIB upozorňuje na zranitelnosti wp2shell (CVE-2026-63030 a CVE-2026-60137) ve WordPress Core, které mohou při kombinovaném zneužití vést ke vzdálenému spuštění kódu bez nutnosti přihlášení.
KEV ✓
EPSS 0.97
CVSS 9.0
CVE-2026-60137
CVE-2026-63030
WordPress
CZ
US
AT
FR
tg: zneužíváno
tg: rozbor
tg: návod
tg: přehled
tp: malware
tp: ransomware
14. 8. 15:30 · NÚKIB · Upozorňujeme na řetězec kritických zranitelností „wp2shell“ ve WordPress
23. 7. 20:00 · Cisco Talos · Don’t swing at everything
23. 7. 02:00 · Elastic Security · wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution
20. 7. 11:01 · CERT.at · Kritische Sicherheitslücken in WordPress - Updates verfügbar
20. 7. 02:00 · CERT-FR – alerty · Multiples vulnérabilités dans WordPress (20 juillet 2026)
Shrnutí generováno strojově za 0,0022 USD