How a broken auto-updater left my blog open to a WordPress core RCE (wp2shell, CVE-2026-63030) and the boring IP rule that saved it anyway.
The patch that couldn’t install: a WordPress core exploit created an admin on this blog


How a broken auto-updater left my blog open to a WordPress core RCE (wp2shell, CVE-2026-63030) and the boring IP rule that saved it anyway.