CyberSecurity

WP2Shell: Two Critical WordPress Flaws Already Under Active Attack

Published

on

Critical WordPress Flaws Under Active Exploitation

Two serious vulnerabilities in WordPress are now being actively exploited in the wild. Tracked as CVE-2026-60137 and CVE-2026-63030, the pair has been collectively named WP2Shell by researchers. Attackers began scanning for and exploiting the flaws within hours of their public disclosure.

The bugs were discovered by Searchlight Cyber. According to the firm, every WordPress installation running versions 6.9.0 through 6.9.4, or 7.0.0 through 7.0.1, is vulnerable. That’s a wide swath of the web.

What Makes WP2Shell So Dangerous?

The first flaw, CVE-2026-60137, is a high-severity SQL injection vulnerability. The second, CVE-2026-63030, is a critical arbitrary code execution bug. Alone, each is serious. Chained together, they allow an unauthenticated attacker to execute arbitrary code remotely on a victim’s server.

Searchlight Cyber’s warning was blunt: “The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins.” That means a default WordPress site, with no extra add-ons, is a valid target.

Patches and Automatic Updates Are Live

WordPress released patched versions — 6.9.5 and 7.0.2 — on Friday. Given the severity, the WordPress.org team took an unusual step: they enabled forced automatic updates for all sites running affected versions. This means many site owners may already be protected, even if they haven’t manually updated.

Cloudflare has also deployed detection rules to block exploitation attempts and protect customers who haven’t yet applied the patch.

PoC Exploits Leaked Quickly

Searchlight Cyber deliberately withheld technical details to prevent abuse. It didn’t matter. Proof-of-concept exploit code surfaced from other sources within hours of the patch’s release. The window between disclosure and weaponization is shrinking fast.

Confirmed Attacks in the Wild

Multiple security firms have confirmed active exploitation. Patchstack, a WordPress-focused security company, verified the attacks. Hexastrike reported seeing exploitation attempts in its honeypots over the weekend and had already assisted with incident response for several victims by Sunday.

WatchTowr also observed widespread scanning and exploitation attempts. Benjamin Harris, the company’s CEO and founder, told SecurityWeek: “This is going to hurt. WordPress runs on hundreds of millions of websites globally. Some of those will be auto-patched by their hosting providers, but plenty will not, and that is where the damage will be done.”

AI-Assisted Tooling Speeds Up the Attack Cycle

Harris noted a broader trend behind this incident. “This is also the latest example in a clear trend of vulnerabilities being surfaced by AI-assisted tooling, representing a significant shift in both how our industry finds these issues and how quickly attackers weaponize them. We saw PoCs appear within hours of disclosure, where historically that would have taken 24 hours or more. The window between disclosure and exploitation has collapsed, and WordPress is simply today’s reminder of it.”

That’s a sobering observation. Attackers are now using AI to reverse-engineer patches and generate exploit code almost instantly. Defenders need to move faster than ever.

What WordPress Site Owners Should Do Now

If your site is on a managed WordPress host, check whether the forced automatic update has already been applied. Many hosts push critical patches within hours. If you manage your own installation, update to WordPress 6.9.5 or 7.0.2 immediately.

After updating, audit your site for signs of compromise. Hexastrike has published detection guidance. Look for unexpected admin users, suspicious files, and unusual database queries. If you find anything, treat it as a full compromise and rotate all credentials.

The WP2Shell vulnerabilities are a reminder that even the world’s most popular CMS isn’t immune to critical flaws. The difference between safety and a takeover now comes down to hours — not days.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version