Virtual Event Today: CodeSecCon - Learn to Secure Your Software > Join Event
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

WP2Shell WordPress Vulnerabilities Exploited in the Wild

Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure.

WordPress vulnerability exploited

Two newly patched WordPress vulnerabilities are being exploited in the wild, with attacks beginning shortly after they came to light. 

The vulnerabilities have been dubbed WP2Shell and they are officially tracked as CVE-2026-60137 and CVE-2026-63030. 

According to Searchlight Cyber, whose researchers discovered the flaws, WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected. 

“The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins,” the security firm warned.

WordPress announced patches on Friday with the release of versions 6.9.5 and 7.0.2. 

“Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions,” WordPress developers said. 

Advertisement. Scroll to continue reading.

Cloudflare has also rolled out rules to detect exploitation and protect customers whose installations were not immediately patched. 

CVE-2026-60137 is a high-severity SQL injection bug and CVE-2026-63030 is a critical arbitrary code execution vulnerability. Chaining the two flaws enables an attacker to achieve unauthenticated remote code execution on affected WordPress websites. Threat actors can exploit these vulnerabilities to take control of targeted sites. 

While Searchlight Cyber has not made public any details to prevent abuse, PoC exploits have already been made public by others. 

WP2Shell exploited in the wild

The in-the-wild exploitation of the WP2Shell vulnerabilities has been confirmed by several cybersecurity firms. One of them is the WordPress security company Patchstack.

Hexastrike started seeing exploitation attempts in its honeypots over the weekend, and on Sunday the company said it had already assisted with incident response in several attacks. Hexastrike has shared some recommendations for detecting and investigating intrusions.

WatchTowr has also seen in-the-wild exploitation attempts.  

“This is going to hurt,” the company’s CEO and founder, Benjamin Harris, told SecurityWeek. “WordPress runs on hundreds of millions of websites globally. Some of those will be auto-patched by their hosting providers, but plenty will not, and that is where the damage will be done.”

Harris added, “This is also the latest example in a clear trend of vulnerabilities being surfaced by AI-assisted tooling, representing a significant shift in both how our industry finds these issues and how quickly attackers weaponize them. We saw PoCs appear within hours of disclosure, where historically that would have taken 24 hours or more. The window between disclosure and exploitation has collapsed, and WordPress is simply today’s reminder of it.”

Related: Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data

Related: 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown

Related: Everest Forms Vulnerability Exploited to Hack WordPress Sites

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Dali Rajic is joining OpenAI as Chief Revenue Officer.

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.