# wp2shell (CVE-2026-63030, CVE-2026-60137): Frequently asked questions about remote code execution chain in WordPress Core

> Quelle: Tenable Research — https://www.tenable.com/blog/wp2shell-cve-2026-63030-cve-2026-60137-frequently-asked-questions-about-remote-code-execution

## Maßnahmen

- [ ] Betroffenheit im eigenen Stack prüfen (CVE-2019-9978, CVE-2020-11738, CVE-2020-25213, CVE-2026-41940, CVE-2026-60137): Versionen/Komponenten abgleichen.
- [ ] Originalquelle / Hersteller-Advisory lesen: https://www.tenable.com/blog/wp2shell-cve-2026-63030-cve-2026-60137-frequently-asked-questions-about-remote-code-execution
- [ ] Priorität HOCH: laut CISA-KEV aktiv ausgenutzt – bevorzugt patchen.
- [ ] Verfügbaren Patch oder Workaround einspielen und dokumentieren.
- [ ] Erkennung: Logs und Indikatoren (IoCs) auf Ausnutzung prüfen.
