
One Request Could Hijack Your WordPress Site
On 17 July 2026 WordPress shipped forced updates 6.9.5 and 7.0.2 to close wp2shell (CVE-2026-63030), a pre-authentication remote code execution flaw in core that an anonymous request could trigger on a default install. Why the automatic patch is not where your job ends.










