← nejvýznamnější zprávy · všechny zprávy

SPOJENO PŘES CVE KEV ✓ (2 z 2) EPSS 0.97 (nejvyšší)

Upozorňujeme na řetězec kritických zranitelností „wp2shell“ ve WordPress

Upozorňujeme na dvojici zranitelností ve WordPress Core označovaných jako wp2shell (CVE-2026-63030 a CVE-2026-60137), které mohou při kombinovaném zneužití vést ke vzdálenému spuštění kódu (RCE) bez nutnosti přihlášení.

Číst originál na NÚKIB →

6 zpráv z 5 zdrojů · první 20. 7. 02:00 · poslední 14. 8. 15:30 CZ · EN/orig

WordPress CZ US AT FR

tg: zneužíváno tg: rozbor tg: návod tg: přehled tp: malware tp: ransomware

CVE v události 2

CVEhodnoceníKEVEPSS
CVE-2026-60137 9.1 3.1 · CISA-ADP 5.9 3.1 · WPScan KEV ✓ 0.78
CVE-2026-63030 9.8 3.1 · WPScan 7.5 3.1 · CISA-ADP KEV ✓ 0.97

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 9.0.

Jak se o tom psalo 6

  1. · NÚKIB CZ nadpis události

    Upozorňujeme na řetězec kritických zranitelností „wp2shell“ ve WordPress

    Upozorňujeme na dvojici zranitelností ve WordPress Core označovaných jako wp2shell (CVE-2026-63030 a CVE-2026-60137), které mohou při kombinovaném zneužití vést ke vzdálenému spuštění kódu (RCE) bez nutnosti přihlášení.

  2. · Cisco Talos US

    Don’t swing at everything

    Welcome to this week’s edition of the Threat Source newsletter. Lately I've found myself thinking a lot about the Australian TV series Mr. Inbetween (IMDb 8.7/10) — not because I'm a hitman for hire, but because I literally feel in-between. Specifically, in-between what I'd call the "pre-Mythos" and “post-Mythos” eras. We've crossed a capability threshold, and it's not just one model family driving that — Codex 5.3 and GPT-5.5 deliver comparable or better performance, and Tulongfeng or GLM-5.2 …

  3. · Elastic Security US

    wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution

    On July 17, 2026, Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution chain in WordPress Core (CVE-2026-63030, CVE-2026-60137). Proof-of-concept tools hit GitHub within hours. hashkitten published the chain after PoCs started circulating, including a write-up of how the bug was found. Scanning followed immediately, and we are already seeing the same host footprint in customer telemetry: PHP and web server runtimes spawning shells, plugin directories appearing under…

  4. · Elastic Security US

    wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution

    On July 17, 2026, Searchlight Cyber disclosed wp2shell, a pre-authentication remote code execution chain in WordPress Core (CVE-2026-63030, CVE-2026-60137). Proof-of-concept tools hit GitHub within hours. hashkitten published the chain after PoCs started circulating, including a write-up of how the bug was found. Scanning followed immediately, and we are already seeing the same host footprint in customer telemetry: PHP and web server runtimes spawning shells, plugin directories appearing under…

  5. · CERT.at AT

    Kritische Sicherheitslücken in WordPress - Updates verfügbar

    20. Juli 2026 Beschreibung In WordPress existieren zwei Sicherheitslücken. Eine SQL-Injection-Schwachstelle im Parameter „author__not_in“ von „WP_Query“ betrifft WordPress ab Version 6.8. Ab WordPress 6.9 lässt sich diese laut Advisory in Kombination mit einer Schwachstelle in der REST-API (Batch-Route-Confusion) zur Ausführung von beliebigem Code (Remote Code Execution) ausnutzen. Laut Searchlight Cyber ist diese Angriffskette ohne vorherige Authentifizierung und ohne weitere Voraussetzungen…

  6. · CERT-FR – alerty FR

    Multiples vulnérabilités dans WordPress (20 juillet 2026)

    Le 17 juillet 2026, WordPress a publié un correctif pour deux vulnérabilités : CVE-2026-60137 : une injection SQL (SQLi) ; CVE-2026-63030 : celle-ci permet un contournement de la politique de sécurité. Un attaquant peut exploiter ces deux vulnérabilités, de manière combinée, pour obtenir une...