WordPress has released security updates 6.9.5 and 7.0.2 to address two critical vulnerabilities, wp2shell, which together allow for remote code execution on default installations. These flaws, CVE-2026-63030 and CVE-2026-60137, affect specific versions of WordPress and can lead to complete website compromise without requiring user interaction. Notably, an AI model was used to discover one of the vulnerabilities and develop an exploit, leading to a rapid exploitation trend where Proofs of Concept appeared within hours, significantly faster than usual. AI
IMPACT Accelerates the trend of AI-discovered vulnerabilities being exploited rapidly, pressuring organizations to improve their patching cadences.
RANK_REASON Security patch for a widely used software product, with an AI angle on discovery and exploitation speed.
Read on Mastodon — fosstodon.org →
- Adam Kues
- Benjamin Harris
- CVE-2026-60137
- CVE-2026-63030
- Hugging Face
- OpenAI
- VulnCheck
- watchTowr
- WordPress
- wp2shell
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →