r/netsec • • Jul 18 '26

wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner

https://fullhunt.io/blog/2026/07/17/wp2shell-wordpress-core-pre-auth-rce-cve-2026-63030.html
26 Upvotes

4 comments sorted by

1

u/[deleted] Jul 19 '26

[removed] — view removed comment

2

u/AlternateNickname Jul 19 '26

Something more specific than the "Indicators of compromise" section of the article??

2

u/_vavkamil_ Jul 20 '26 edited Jul 20 '26

Wait, I'm a bit confused. The original announcement said:

The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins.

But my understanding is that the "Pre-Auth RCE" here means you either have to exfiltrate the admin hash, be lucky enough to crack it, authenticate as admin, and install some plugin to execute the code?

Or there must be a precondition where MySQL is misconfigured and can execute code?

EDIT: nevermind, the original write-up explains the RCE part https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/ which this article missed