# Security Brief: WP2Shell WordPress Core Chain Enables Administrator Creation and RCE

Canonical: https://vulnify.app/blog/security-brief-wp2shell-wordpress-core-chain-admin-rce

The WP2Shell chain combines CVE-2026-60137 and CVE-2026-63030 to turn unauthenticated WordPress flaws into administrator creation and potential remote code execution. Real attack activity has been observed.

What happened Wordfence has published technical analysis and real-world attack data for the WordPress vulnerability chain commonly referred to as WP2Shell. The chain combines CVE-2026-60137, an unauthenticated SQL injection flaw, with CVE-2026-63030, a REST API batch-request route-confusion issue. When chained on affected WordPress versions, an unauthenticated attacker can create an administrator account and then use normal administrator capabilities, such as plugin installation, to execute code. The SQL injection affects WordPress 6.8 through 6.8.5, 6.9 through 6.9.4, and 7.0 through 7.0.1. The route-confusion component affects the 6.9 and 7.0 ranges. Patched releases include 6.8.6, 6.9.5, and 7.0.2. Wordfence reported more than 11 million blocked exploit attempts in its protected customer telemetry. Why it matters for website owners The chain shows how two weaknesses can create a much more serious outcome together. Database injection provides a foothold, while the REST routing issue raises the impact to administrator creation. An attacker who becomes a WordPress administrator can upload malicious plugins or themes and take control of site content and server-side application behavior. What to check on your site Confirm WordPress core is on a patched release for the branch you use. Review administrator accounts for unexpected users and recent privilege changes. Inspect plugin and theme installations for unfamiliar additions and review recently modified PHP files. Check access logs for unusual REST batch activity and suspicious requests involving author query parameters. Use the WordPress Stack Checker to review the site's publicly visible WordPress footprint and component signals. Direct server and admin access are still required to verify compromise. Related reading For broader WordPress risk context, see Five Critical WordPress Flaws Enable Administrator Takeover and Remote Code Execution . After patching, use the Post-Deployment Website Security Checklist to confirm the intended release is live. Sources Wordfence
