IT Alert
Security Alert - Critical WordPress Update (wp2shell)
CVE-2026-63030 + CVE-2026-60137 · Pre-auth WordPress Core RCE chain used as initial access to deploy Agent-TCP, a cross-platform Go RAT, across Windows & Linux — combined with mass IoT compromise across 14 CPU architectures, fileless execution via MemfdCreate, and DLL injection on Windows.
Affected: WordPress 6.9.0–7.0.1. Fixed: 7.0.2 / 6.9.5. It is recommended that you update your sites immediately: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
References:
https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
https://blog.offensive-intel.com/cross-platform-rat-deployment-via-wp2shell/#wordpress
Affected: WordPress 6.9.0–7.0.1. Fixed: 7.0.2 / 6.9.5. It is recommended that you update your sites immediately: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
References:
https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
https://blog.offensive-intel.com/cross-platform-rat-deployment-via-wp2shell/#wordpress

