Everyone's telling you the same thing right now: update WordPress. Which is, fine, yes, obviously but...

By chaining an SQL injection and an API vulnerability, attackers can inject code. WordPress has released an update, the finders a hotfix.

In-the-wild exploitation seen for the new WP2Shell WordPress vulnerabilities, officially tracked as CVE-2026-60137 and CVE-2026-63030.