
CISA Warns of Actively Exploited WordPress Flaws Enabling Pre-Auth RCE
CISA has added two chained WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, to its Known Exploited Vulnerabilities (KEV) catalog, warning that the flaws enable unauthenticated, pre-auth remote code execution (RCE) on default WordPress installations now being actively targeted. The flaw CVE-2026-63030, dubbed “wp2shell”, is a pre-authentication RCE vulnerability that impacts WordPress Core 6.8.x, 6.9.x and 7.0.x […]
The post CISA Warns of Actively Exploited WordPress Flaws Enabling Pre-Auth RCE appeared first on Cyber Security News.