Overview Recently, NSFOCUS CERT detected that WordPress issued a security bulletin to fix the WordPress remote code execution vulnerability (CVE-2026-63030/CVE-2026-60137), known as wp2shell; Unauthenticated attackers can bypass authentication through REST API batch requests, use SQL injection to obtain administrator password hashes, and use plug-in installation functions to implant WebShell to...
Tag: WordPress
WordPress plug-in authentication bypass vulnerability Security Alert
Overview Recently, webarx researchers announced two high-risk authentication bypass vulnerabilities in WordPress plug-ins, which allow attackers to log in to an administrator account without a password. (mais…)

