WordPress patches wp2shell pre-auth RCE in 7.0.2 and 6.9.5
WordPress 7.0.2 and 6.9.5 shipped July 17 to close CVE-2026-63030 — a pre-auth RCE in Core built on the CVE-2026-60137 SQL injection. Detection PoC is already public.
WordPress 7.0.2 and 6.9.5 shipped July 17 to close CVE-2026-63030 — a pre-auth RCE in Core built on the CVE-2026-60137 SQL injection. Detection PoC is already public.
Wordfence blocked 17M attempts at the unauth REST endpoint that dumps Gravity SMTP's full System Report — live API keys and OAuth tokens included. Patch is 2.1.5.
Wordfence's firewall blocked 29,300+ exploit attempts against a CVSS 9.8 PHP-eval RCE in Everest Forms Pro. Sites pre-1.9.13 should hunt for the rogue admin diksimarina.