Critical Unauthenticated RCE in WordPress (CVE‑2026‑63030 & CVE‑2026‑60137) Powers wp2shell Exploits
What It Is — Two newly disclosed WordPress core flaws (codenamed wp2shell) allow an attacker with no credentials to execute arbitrary code on the underlying server. When chained, the vulnerabilities give full compromise of vulnerable sites.
Exploitability — Public exploit code was released on GitHub; mass‑scanning activity was observed within hours of disclosure. CVSS v3.1 scores are 9.8 (Critical) for both CVEs.
Affected Products — WordPress core versions 6.2‑6.4 (pre‑patch) on any hosting environment that has not applied the security updates published on 2026‑07‑15.
Why It Matters for Compliance & Audit Readiness
- SOC 2 requires a documented vulnerability‑management program (CC6.1). Rapid patching of these critical CVEs is evidence of an effective risk‑mitigation process.
- Continuous monitoring of web‑application assets and retaining remediation logs provides a defensible audit trail that auditors will request.
- Third‑party SaaS or managed‑hosting providers that run WordPress must demonstrate vendor‑risk controls; unpatched sites constitute a control gap that can be flagged in a SOC 2 audit.
Recommended Actions
- Inventory every WordPress instance, confirm the exact version, and apply the official patches for CVE‑2026‑63030 and CVE‑2026‑60137 immediately.
- Deploy a Web‑Application Firewall (WAF) with rules that block the known wp2shell payloads and log any attempts.
- Capture remediation evidence (patch logs, WAF alerts) in your SOC 2 evidence repository and map the activity to the vulnerability‑management control.
Source: The Hacker News