A pair of newly patched WordPress vulnerabilities is being actively exploited by attackers, with multiple cybersecurity firms confirming that malicious actors have successfully compromised affected websites. The flaws, known as WP2Shell, were first disclosed just days ago and have already been chained together to achieve unauthenticated remote code execution on vulnerable sites.
The two vulnerabilities, officially tracked as CVE-2026-60137 and CVE-2026-63030, affect WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. A high-severity SQL injection bug and a critical arbitrary code execution vulnerability, respectively, they can be exploited by an attacker with no prior knowledge or privileges on the affected website.
Searchlight Cyber, the firm that discovered the flaws, warned of the attack’s simplicity: “The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins.” This ease of exploitation is particularly concerning, given that WordPress runs on hundreds of millions of websites globally. While some sites may receive auto-patches from their hosting providers, many others will remain vulnerable until their administrators apply the necessary updates.
The exploitation of WP2Shell has been confirmed by multiple cybersecurity firms, including WatchTowr and Patchstack. Hexastrike, a security company that provides honeypot services to detect and analyze cyber threats, reported seeing exploitation attempts over the weekend and assisting with incident response in several attacks. The company’s CEO, Benjamin Harris, warned of the significant damage that could be done: “This is going to hurt… Some of those [websites] will be auto-patched by their hosting providers, but plenty will not, and that is where the damage will be done.”
The rapid exploitation of WP2Shell highlights a disturbing trend in the cybersecurity landscape. As AI-assisted tooling becomes increasingly prevalent, vulnerabilities are being discovered and exploited at an unprecedented rate. “The window between disclosure and exploitation has collapsed,” Harris noted. This shift underscores the need for website administrators to stay vigilant and apply security patches promptly.
To protect themselves from the ongoing threat of WP2Shell exploitation, website owners should prioritize updating their WordPress installations to versions 6.9.5 or 7.0.2, which include the necessary patches. Additionally, Cloudflare has rolled out rules to detect exploitation and protect customers whose installations were not immediately patched. By taking these steps, site administrators can minimize their risk of falling victim to this critical vulnerability.
In conclusion, the rapid exploitation of WP2Shell serves as a stark reminder that cybersecurity threats are evolving at an alarming rate. As website owners, it is essential to stay informed about vulnerabilities and take proactive measures to protect against them. By doing so, we can mitigate the impact of such attacks and ensure the continued security and integrity of our online presence.
Source: SecurityWeek — 2026-07-20