Wordfence Intelligence Weekly WordPress Vulnerability Report (July 13, 2026 to July 19, 2026)

Last week, there were 75 vulnerabilities disclosed in WordPress Core, 68 WordPress Plugins and no WordPress themes that have been added to the Wordfence Intelligence Vulnerability Database, and there were 50 Vulnerability Researchers that contributed to WordPress Security last week. Review those vulnerabilities in this report now to ensure your site is not affected. Our … Read more

WordPress 7.1 Beta 3

WordPress 7.1 Beta 3 is ready for download and testing!  This beta release is intended for testing and development only. Please do not install, run, or test this version of WordPress on production or mission-critical websites. Instead, use a test environment or local site to explore the new features. How to Test WordPress 7.1 Beta … Read more

wp2shell Aftermath: The First Critical Unauthenticated WordPress Core RCE in Nearly a Decade

On Friday, July 17, 2026, the WordPress Security Team released security updates for WordPress Core addressing two vulnerabilities that, when chained together, can lead to unauthenticated remote code execution. The chain, now commonly referred to as wp2shell, was discovered and reported by Adam Kues of Assetnote / Searchlight Cyber, and we want to thank him … Read more

PSA: WordPress Core Patched Unauthenticated Remote Code Execution Vulnerability Chain

On July 17, 2026, the WordPress Security Team released updates to WordPress core addressing two security vulnerabilities. The first is an unauthenticated SQL injection vulnerability identified as CVE-2026-60137, while the second can be chained with the SQL injection to increase its impact to unauthenticated remote code execution and is identified as CVE-2026-63030. To protect WordPress … Read more