CVE-2026-63030
WP2Shell: REST API batch-route confusion -> SQLi (CVE-2026-60137) -> unauthenticated RCE
- Severity
- critical
- Affected product
- WordPress
- Affected versions
- WordPress ≥ 6.9, < 6.9.5
- Affected versions
- WordPress ≥ 7.0, < 7.0.2
- Fixed in
- WordPress 6.9.5
- Fixed in
- WordPress 7.0.2
- Added to NewScan
- 2026-07-19
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
Version-match only; a batch-endpoint probe wouldn't confirm (patched builds serve /batch/v1 too), and the SQLi/RCE can't be triggered non-destructively. 7.1 beta is also affected but its version string is transient, so it is not range-matched.
COMPONENT VERSION RANGE
NewScan fingerprints WordPress from its response and reports this CVE when the detected version falls inside the affected range below.
Version-match only; a batch-endpoint probe wouldn't confirm (patched builds serve /batch/v1 too), and the SQLi/RCE can't be triggered non-destructively. 7.1 beta is also affected but its version string is transient, so it is not range-matched.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →