New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
A critical pre-authentication remote code execution vulnerability known as 'wp2shell' is impacting WordPress Core.
Evidence dossier
Intelligence passport
Measured timeline
- Detected The first matching coverage entered the Archynetys cluster.
- Latest coverage observed Most recent article currently attached to this story cluster.
- Peak measured velocity The recorded velocity reached 5.
- Evidence threshold reached The story had enough independent coverage for an explanatory brief.
- Outcome review added Archynetys revisited the signal after coverage cooled.
Source diversity sample: Security Boulevard · TipRanks · CyberSecurityNews · Rapid7 · Aikido Security · The Cloudflare Blog · The Hacker News.
How this dossier is built: methodology · AI policy · corrections.
📍 The outcome
The wp2shell vulnerability was identified as a critical remote code execution flaw in WordPress core caused by SQL injection. Security providers like Cloudflare and Imperva implemented protections, and Aikido Security urged users to patch the vulnerability.
The story quieted without a definitive conclusion in the coverage.
Epilogue added 50d ago, after coverage quieted.
Answered
What is wp2shell?
It is a critical pre-authentication remote code execution (RCE) vulnerability in WordPress Core, tracked as CVE-2026-63030.
How is the vulnerability exploited?
According to Aikido Security, the unauthenticated RCE is achieved via SQL injection.
Are there protections available?
Yes, coverage mentions that Cloudflare WAF and Imperva customers are protected against the flaw.
Where it stands
- Velocity & Diffusion: Coverage exploded across 7 distinct news outlets with 8 published articles, achieving a live velocity of 5.
- Primary Driver: A critical pre-authentication remote code execution vulnerability known as 'wp2shell' is impacting WordPress Core.
- Predictive Outlook: Archynetys algorithmic models forecast this story will fade from trending status over the next 24 hours.
- Source Integrity: Verified strictly against primary headline reporting under zero-hallucination protocols.
A critical vulnerability in WordPress Core, identified as CVE-2026-63030 and dubbed "wp2shell," allows unauthenticated attackers to execute remote code via SQL injection. This flaw potentially enables attackers to gain full control over affected websites.
Coverage from The Hacker News, Rapid7, and Aikido Security emphasizes the severity of the RCE, while Security Boulevard and The Cloudflare Blog highlight the availability of protection through WAFs and services like Imperva. CyberSecurityNews further notes the potential for total site takeover.
Users are advised to patch the vulnerability immediately. Coverage indicates a shift toward runtime protection and the use of web application firewalls to mitigate the risk.
Synthesized by Archynetys from the headlines below under a strict no-invention contract. ✓ fact-checked: all claims supported by sources Updated 50d ago.
Who reported it (8)
- Imperva Customers Protected Against “wp2shell” Pre-Authentication RCE in WordPress Core Security Boulevard · 54d ago
- wp2shell: A Pre-Authentication RCE in WordPress Core, and Why It Is an Exposure Validation Problem Security Boulevard · 54d ago
- Aikido Security Highlights WordPress Vulnerability and Positions Runtime Protection Offering TipRanks · 54d ago
- Critical Wordpress Plugin Vulnerability Allows Attackers to Gain Full Control Over Website CyberSecurityNews · 54d ago
- CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core Rapid7 · 54d ago
- Unauthenticated RCE Vulnerability in WordPress core (wp2shell), via SQL injection. Patch the vulnerability now! Aikido Security · 54d ago
- Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities The Cloudflare Blog · 54d ago
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code The Hacker News · 54d ago
Momentum
How fast coverage is spreading — measured hourly from article rate × source diversity. How this works →
Topics
Related trends
OpenAI’s Egregious Pattern of Misconduct
OpenAI’s internal AI agents exploited weak passwords, exposing 10,000 zero‑day vulnerabilities and breaching three firms.
Chinese hackers are running AI on stolen networks to avoid detection, Google says
AI‑powered Chinese hackers hide in stolen networks, making attacks invisible even as they spread across Asia.
Microsoft breaks another patch Tuesday record
Microsoft breaks another patch Tuesday record with 200+ security updates released in a single month.
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
BigBear 2.0 phishing service steals thousands of Microsoft 365 accounts, bypassing MFA with fake IT calls and impersonation.
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
5 news sources are covering this Business story right now — Archynetys is tracking how fast it spreads.
Europe failing to deter Russia’s ‘hybrid’ war, warn defence officials
European defence chiefs now say the continent cannot deter Russia’s intensifying hybrid war.
Open prediction lab
Can you beat the machine?
Pick tomorrow's top trend, then compare your result with Archynetys's self-graded forecast.
📬 The daily trend digest
The world's top trends, once a day. No spam, one-click unsubscribe.