Уязвимост wp2shell засягащa WordPress
Cybersecurity Classified by Officially
wp2shell представлява комбинация от 2 уязвимости за WordPress, които като бъдат екслоатирани водят до unauthenticated remote code execution (RCE) и могат да доведат до компрометирането на уязвими уебсайтове.
wp2shell използва критична pre-authentication remote code execution грешка в ядрото на WordPress, а не на някой от plug-in-те или теми за WordPress.
Уязвимостите, които използва wp2shell са SQL инжекция в author__not_in параметъра на WP_Query (CVE-2026-60137), комбинирана с REST API batch route confusion в /wp-json/batch/v1 (CVE-2026-63030).
Уязвимите версии на WordPress са 6.9.0 – 6.9.4 и 7.0.0 – 7.0.1.
CERT България Ви препоръчва ако използвате засегнатите версии на WordPress да ги актуализирате възможно най-скоро. Ако не можете да актуализирате веднага, тогава блокирайте /wp-json/batch/v1 and ?rest_route=/batch/v1 през WAF.
За повече информация:
https://labs.eye.security/wp2shell-defenders-guide/
https://socradar.io/blog/wp2shell-wordpress-rce-cve-2026-63030/
This is an extract. The publication continues at the source.
Read the original at the source: https://www.govcert.bg/warnings/wp2shell-wordpress/
Officially imported this from CERT Bulgaria (GovCERT)’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- CERT Bulgaria (GovCERT) — imported from official source
- Official source
- https://www.govcert.bg/feed/ RSS
- Imported
- October 03, 2026 20:33
- Versions
- 1 recorded
- Identity
https://www.govcert.bg/?p=4545