WordPress released emergency updates 7.0.2 and 6.9.5 to fix critical pre-authentication remote code execution flaw CVE-2026-63030 (“wp2shell”), affecting core versions 6.9.0–6.9.4 and 7.0.0–7.0.1. Version 6.8.6 patches related SQL injection CVE-2026-60137. Most default sites are vulnerable without persistent object cache. Administrators should update immediately or temporarily block REST batch endpoints if patching is delayed.
Trending
- Piyush Goyal Highlights India’s Growth, Seeks Deeper Trade Ties With Estonia
- Piyush Goyal Calls for Stronger India-Estonia Trade and Technology Partnership at Tallinn Business Forum
- Steptrade Capital Secures ₹100 Crore First Close for ₹500 Crore Chanakya Opportunities Fund II
- Steptrade Capital’s Chanakya Opportunities Fund II Hits First Close, Crosses ₹100 Crore in Commitments in Three Months
- India, Spain Begin Talks to Link UPI With Bizum for Cross-Border Payments
- India, Spain Begin Talks to Link UPI With Bizum for Cross-Border Payments
- Moonshot AI Halts New Kimi K3 Subscriptions as GPU Load Peaks
- Moonshot AI Pauses New Kimi K3 Subscriptions After GPU Capacity Hits Demand Limits

