WordPress 7.0.2 wp2shell
Incident Lifecycle
Incident Timeline
Monitoring
We are continuing to monitor traffic patterns and adapt network-level mitigations in response.
Jul 21, 2026 at 1:43 PM UTC
Monitoring
We can observe our mitigations denying an increasing volume of requests and are continuing to gather data to enhance our response.
We will provide an update Tuesday morning.
We will provide an update Tuesday morning.
Jul 20, 2026 at 10:20 PM UTC
Monitoring
Summary
On July 17, 2026, the WordPress security team disclosed two chained vulnerabilities in WordPress core, publicly referred to as "wp2shell":
- CVE-2026-60137 — a SQL injection issue in WordPress core (WP_Query / author__not_in).
- CVE-2026-63030 — a REST API batch-route confusion issue which, chained with the above, can lead to unauthenticated remote code execution.
Who is affected
This affects specific versions of WordPress core:
- 6.9.x — affected by both issues (RCE-capable...
On July 17, 2026, the WordPress security team disclosed two chained vulnerabilities in WordPress core, publicly referred to as "wp2shell":
- CVE-2026-60137 — a SQL injection issue in WordPress core (WP_Query / author__not_in).
- CVE-2026-63030 — a REST API batch-route confusion issue which, chained with the above, can lead to unauthenticated remote code execution.
Who is affected
This affects specific versions of WordPress core:
- 6.9.x — affected by both issues (RCE-capable...
Jul 20, 2026 at 7:26 PM UTC
Was your business affected by this Pantheon outage?
Follow Pantheon and route available status alerts to email or a team channel.