Ninety minutes, then four days: the WordPress core RCE from a different perspective
On July 17, Patchstack published an account of how quickly attackers weaponised the WordPress core RCE chain — CVE-2026-60137 and CVE-2026-63030 — measuring roughly ninety minutes from public patch to live exploitation attempts. Their post closed with a section on what to grep for in your own logs. We took them up on it. Sitting…
