We're writing to make you aware of a critical security vulnerability affecting WordPress core, tracked as CVE-2026-63030 (also known as "wp2shell"). It is a pre-authentication remote code execution flaw: an attacker needs no login, no plugin, and no user interaction to exploit a vulnerable site. It is being actively exploited in the wild, and ...
Continue reading