Key Findings Two critical WordPress Core vulnerabilities (CVE-2026-63030 and CVE-2026-60137) can be chained together to achieve pre-authentication remote code execution Public exploits are now available for the wp2shell attack chain Affected versions are WordPress 6.9.0-6.9.4 and 7.0.0-7.0.1 WordPress has enabled forced automatic security updates due to severity Over 500 million websites worldwide use WordPress and are potentially at risk No plugins or valid credentials requi