SPOJENO PŘES CVE KEV ✓ (2 z 2) EPSS 0.97 (nejvyšší)
Upozorňujeme na řetězec kritických zranitelností „wp2shell“ ve WordPress
Upozorňujeme na dvojici zranitelností ve WordPress Core označovaných jako wp2shell (CVE-2026-63030 a CVE-2026-60137), které mohou při kombinovaném zneužití vést ke vzdálenému spuštění kódu (RCE) bez nutnosti přihlášení.
WordPress CZ US AT FR
CVE v události 2
| CVE | hodnocení | KEV | EPSS |
|---|---|---|---|
| CVE-2026-60137 | 9.1 3.1 · CISA-ADP 5.9 3.1 · WPScan | KEV ✓ | 0.78 |
| CVE-2026-63030 | 9.8 3.1 · WPScan 7.5 3.1 · CISA-ADP | KEV ✓ | 0.97 |
Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.0.
Jak se o tom psalo 6
-
· NÚKIB CZ nadpis události
Upozorňujeme na řetězec kritických zranitelností „wp2shell“ ve WordPress
Upozorňujeme na dvojici zranitelností ve WordPress Core označovaných jako wp2shell (CVE-2026-63030 a CVE-2026-60137), které mohou při kombinovaném zneužití vést ke vzdálenému spuštění kódu (RCE) bez nutnosti přihlášení.
-
· Cisco Talos US
Don’t swing at everything
Welcome to this week’s edition of the Threat Source newsletter. Lately I've found myself thinking a lot about the Australian TV series Mr. Inbetween (IMDb 8.7/10) — not because I'm a hitman for hire, but because I literally feel in-between. Specifically, in-between what I'd call the "pre-Mythos" and “post-Mythos” eras. We've crossed a capability threshold, and it's not just one model family driving that — Codex 5.3 and GPT-5.5 deliver comparable or better performance, and Tulongfeng or GLM-5.2 …
-
· Elastic Security US
wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution
On July 17, 2026, Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution chain in WordPress Core (CVE-2026-63030, CVE-2026-60137). Proof-of-concept tools hit GitHub within hours. hashkitten published the chain after PoCs started circulating, including a write-up of how the bug was found. Scanning followed immediately, and we are already seeing the same host footprint in customer telemetry: PHP and web server runtimes spawning shells, plugin directories appearing under…
-
· Elastic Security US
wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution
On July 17, 2026, Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution chain in WordPress Core (CVE-2026-63030, CVE-2026-60137). Proof-of-concept tools hit GitHub within hours. hashkitten published the chain after PoCs started circulating, including a write-up of how the bug was found. Scanning followed immediately, and we are already seeing the same host footprint in customer telemetry: PHP and web server runtimes spawning shells, plugin directories appearing under…
-
· CERT.at AT
Kritische Sicherheitslücken in WordPress - Updates verfügbar
20. Juli 2026 Beschreibung In WordPress existieren zwei Sicherheitslücken. Eine SQL-Injection-Schwachstelle im Parameter „author__not_in“ von „WP_Query“ betrifft WordPress ab Version 6.8. Ab WordPress 6.9 lässt sich diese laut Advisory in Kombination mit einer Schwachstelle in der REST-API (Batch-Route-Confusion) zur Ausführung von beliebigem Code (Remote Code Execution) ausnutzen. Laut Searchlight Cyber ist diese Angriffskette ohne vorherige Authentifizierung und ohne weitere Voraussetzungen…
-
· CERT-FR – alerty FR
Multiples vulnérabilités dans WordPress (20 juillet 2026)
Le 17 juillet 2026, WordPress a publié un correctif pour deux vulnérabilités : CVE-2026-60137 : une injection SQL (SQLi) ; CVE-2026-63030 : celle-ci permet un contournement de la politique de sécurité. Un attaquant peut exploiter ces deux vulnérabilités, de manière combinée, pour obtenir une...