WordPress
Vulnerabilities across WordPress core and its plugin and theme ecosystem — the sprawling third-party attack surface that runs a large share of the public web, where a single popular plugin flaw can cascade into hundreds of thousands of compromised sites within days of disclosure.
WordPress WP_Query author__not_in SQL injection (wp2shell companion)
A medium-severity SQL injection in WordPress WP_Query's author__not_in parameter (CVE-2026-60137). Tracked as the wp2shell companion. Patched in 6.8.6, 6.9.5, and 7.0.2.
WordPress Core unauthenticated RCE (wp2shell)
A critical unauthenticated remote code execution flaw in WordPress Core (CVE-2026-63030). GitHub Security Advisory issued July 17, 2026; public PoC circulating.

wp2shell: first signs of exploitation; CVE-2026-60137 lands
watchTowr reports first signs of in-the-wild exploitation of the WordPress Core wp2shell RCE. The pending companion CVE-2026-60137 SQLi has landed, and exact patched versions are 6.9.5 and 7.0.2.

WordPress Core RCE (wp2shell): CVE-2026-63030, PoC public
A critical unauthenticated remote code execution flaw in WordPress Core got a CVE, a GitHub advisory, and a working public PoC on July 17, 2026.