Уязвимост wp2shell засягащa WordPress

Imported from official source

Announcement

Cybersecurity Classified by Officially

wp2shell представлява комбинация от 2 уязвимости за WordPress, които като бъдат екслоатирани водят до unauthenticated remote code execution (RCE) и могат да доведат до компрометирането на уязвими уебсайтове.

wp2shell използва критична pre-authentication remote code execution грешка в ядрото на WordPress, а не на някой от plug-in-те или теми  за WordPress.

Уязвимостите, които използва wp2shell са SQL инжекция в  author__not_in параметъра на WP_Query (CVE-2026-60137), комбинирана с REST API batch route confusion в /wp-json/batch/v1 (CVE-2026-63030).

Уязвимите версии на WordPress са 6.9.0 – 6.9.4 и 7.0.0 – 7.0.1.

CERT България Ви препоръчва ако използвате засегнатите версии на WordPress да ги актуализирате възможно най-скоро. Ако не можете да актуализирате веднага, тогава блокирайте /wp-json/batch/v1 and ?rest_route=/batch/v1 през WAF.

За повече информация:

https://labs.eye.security/wp2shell-defenders-guide/

https://socradar.io/blog/wp2shell-wordpress-rce-cve-2026-63030/

This is an extract. The publication continues at the source.

Read the original at the source: https://www.govcert.bg/warnings/wp2shell-wordpress/

Officially imported this from CERT Bulgaria (GovCERT)’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
CERT Bulgaria (GovCERT) — imported from official source
Official source
https://www.govcert.bg/feed/ RSS
Imported
October 03, 2026 20:33
Versions
1 recorded
Identity
https://www.govcert.bg/?p=4545

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.