WordPress released emergency updates 7.0.2 and 6.9.5 to fix critical pre-authentication remote code execution flaw CVE-2026-63030 (“wp2shell”), affecting core versions 6.9.0–6.9.4 and 7.0.0–7.0.1. Version 6.8.6 patches related SQL injection CVE-2026-60137. Most default sites are vulnerable without persistent object cache. Administrators should update immediately or temporarily block REST batch endpoints if patching is delayed.
Trending
- Hugging Face discloses security breach, asks users to rotate tokens and monitor activity
- Hugging Face discloses security breach, asks users to rotate tokens and monitor activity
- MS Dhoni Backs SolarSquare in $53 Million Series C
- MS Dhoni Invests in SolarSquare, Backs India’s Residential Rooftop Solar Growth
- Alibaba Releases Open-Source AI Chip Software Stack, Targeting Nvidia’s CUDA Ecosystem
- Alibaba Open-Sources AI Chip Software Stack to Challenge Nvidia’s CUDA Ecosystem
- OpenAI Temporarily Suspends AI Model After It Bypassed Internal Safety Checks
- OpenAI Temporarily Suspends AI Model After It Bypassed Internal Safety Checks

