WordPress 2 vulnerabilities

Is the WordPress Core plugin safe?

Below are the known, publicly disclosed vulnerabilities of the WordPress Core (WordPress) component. If you use it on your site, check the version and update it before the flaw gets exploited.

Using the WordPress Core plugin? Check for free whether your site is vulnerable through it, or have us update and secure it.

Known vulnerabilities

Wysoka · CVSS 8.9 CVE-2026-64638 August 6, 2026

WordPress Core (XSS2Shell): XSS na logowaniu z ryzykiem wykonania kodu PHP

Affects: WordPress Core 6.4-7.0.2 (i starsze gałęzie)

Pre-auth reflected XSS na ekranie logowania, który w sprzyjających warunkach można rozwinąć do wykonania kodu PHP (RCE). Wymaga interakcji zalogowanego administratora. Poprawka w 7.0.3 oraz w załatanych wersjach starszych gałęzi: natychmiast zaktualizuj rdzeń.

Krytyczna · CVSS 9.8 CVE-2026-63030 July 17, 2026

WordPress Core (wp2shell): nieautoryzowane zdalne wykonanie kodu

Affects: WordPress Core 6.9.0-6.9.4 oraz 7.0.0-7.0.1

Pierwsze od niemal dekady krytyczne RCE w samym rdzeniu WordPressa. Atakujący bez logowania łączy pomylenie tras w REST API (CVE-2026-63030) z SQL injection (CVE-2026-60137) i przejmuje serwer. Aktywnie wykorzystywane: natychmiast zaktualizuj do 6.9.5 / 7.0.2.

How to check whether this affects you

  • Check the installed version of the WordPress Core component in the admin panel.
  • Compare it with the fixed version noted in the details of the relevant vulnerability above.
  • If your version is older, update the component to the latest available.
  • If a fix has not been released yet, temporarily disable the vulnerable element and watch your logs.
Do not guess, check

Is this plugin putting your site at risk?

We will run a free audit: we check versions, plugins and configuration, and tell you plainly whether you are safe.

Request a free audit →