Adam Kues
Coverage of Adam Kues in the Nexus archive.
- Attackers pummel critical WordPress vuln to create all sorts of mischief
Attackers are exploiting two critical WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) to enable pre-authentication remote code execution. The flaws, patched in WordPress versions 6.9.5 and 7.1 Beta 2, allow unauthenticated users to execute arbitrary code by chaining an SQL injection issue with a REST API route confusion bug. Security researchers observed widespread exploitation within hours of the patches being released.
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
A new WordPress core vulnerability named wp2shell allows unauthenticated attackers to execute arbitrary code via an anonymous HTTP request. The flaw exists in the core software, making even installations with no plugins exploitable. WordPress released updates 6.9.5 and 7.0.2 to address the issue, which previously affected all 6.9 and 7.0 versions.