Overview Recently, NSFOCUS CERT detected that WordPress issued a security bulletin to fix the WordPress remote code execution vulnerability (CVE-2026-63030/CVE-2026-60137), known as wp2shell; Unauthenticated attackers can bypass authentication through REST API batch requests, use SQL injection to obtain administrator password hashes, and use plug-in installation functions to implant WebShell to...
