Is the WordPress Core plugin safe?
Below are the known, publicly disclosed vulnerabilities of the WordPress Core (WordPress) component. If you use it on your site, check the version and update it before the flaw gets exploited.
Known vulnerabilities
WordPress Core (XSS2Shell): XSS na logowaniu z ryzykiem wykonania kodu PHP
Pre-auth reflected XSS na ekranie logowania, który w sprzyjających warunkach można rozwinąć do wykonania kodu PHP (RCE). Wymaga interakcji zalogowanego administratora. Poprawka w 7.0.3 oraz w załatanych wersjach starszych gałęzi: natychmiast zaktualizuj rdzeń.
WordPress Core (wp2shell): nieautoryzowane zdalne wykonanie kodu
Pierwsze od niemal dekady krytyczne RCE w samym rdzeniu WordPressa. Atakujący bez logowania łączy pomylenie tras w REST API (CVE-2026-63030) z SQL injection (CVE-2026-60137) i przejmuje serwer. Aktywnie wykorzystywane: natychmiast zaktualizuj do 6.9.5 / 7.0.2.
How to check whether this affects you
- Check the installed version of the WordPress Core component in the admin panel.
- Compare it with the fixed version noted in the details of the relevant vulnerability above.
- If your version is older, update the component to the latest available.
- If a fix has not been released yet, temporarily disable the vulnerable element and watch your logs.
Is this plugin putting your site at risk?
We will run a free audit: we check versions, plugins and configuration, and tell you plainly whether you are safe.
Request a free audit →