This article was collected and archived by Digital Sovereignty Watch from an institutional or public source relevant to digital sovereignty, technology policy, cybersecurity, cloud services, artificial intelligence or European regulation.
Cybersecurity
Critical WordPress Vulnerabilities (wp2shell) — CVE-2026-63030 + CVE-2026-60137
Versions of WordPress prior to 6.9.5 in the 6.9.x series and before 7.0.2 in the 7.0.x series contain two critical vulnerabilities (CVE-2026-63030 and CVE-2026-60137) that, when chained together, allow an unauthenticated attacker to execute arbitrary SQL queries and perform remote code execution on the server. An unauthenticated remote attacker can exploit this chain to fully compromise any unpatched WordPress site, gaining the ability to read, modify, or delete the database and potentially achieve remote code execution on the server. These vulnerabilities are actively being exploited in real attacks! Searchlight Cyber, who discovered the vulnerabilities, has developed a publicly available tool to check if your website is at risk. More information: https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core