WP2Shell WordPress Vulnerabilities Exploited in the Wild

Critical WordPress Vulnerabilities Exploited in the Wild, Thousands at Risk

A pair of newly patched WordPress vulnerabilities has been exploited by attackers, putting hundreds of millions of websites worldwide at risk. The vulnerabilities, dubbed WP2Shell, were first identified as high-severity SQL injection and critical arbitrary code execution flaws, respectively. What’s more alarming is that these bugs have already been chained together to allow unauthenticated remote code execution on affected sites.

The two vulnerabilities, tracked as CVE-2026-60137 and CVE-2026-63030, affect WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. This means that millions of websites are potentially vulnerable to these attacks, with many not even realizing they’re exposed. The good news is that WordPress has released patches for the affected versions, and hosting providers have begun automatically updating sites to protect their users.

However, it appears that some attackers have already been exploiting these vulnerabilities in the wild. Several cybersecurity firms, including Patchstack and Hexastrike, have confirmed in-the-wild exploitation attempts. In fact, Hexastrike has reported assisting with incident response in several attacks over the weekend alone. The company’s CEO, Benjamin Harris, warned that this is just the tip of the iceberg, predicting that many more sites will be compromised unless users take immediate action.

So, how does it work? Simply put, these vulnerabilities allow attackers to inject malicious code into a WordPress site without needing any credentials or permissions. This enables them to execute arbitrary code on the server, effectively gaining control over the website. What’s concerning is that this exploit can be carried out by an anonymous user with no plugins installed, making it a particularly potent threat.

The rapid exploitation of these vulnerabilities highlights a worrying trend in cybersecurity: the increasing speed at which attackers are discovering and exploiting new bugs. In this case, proof-of-concept (PoC) exploits were made public just hours after disclosure, demonstrating the growing power of AI-assisted tooling in finding and weaponizing vulnerabilities.

For site owners and administrators, it’s essential to take immediate action. WordPress has enabled forced updates for affected versions via its auto-update system, but this may not be enough to protect all sites. We recommend checking your website’s version and updating to the latest patched version as soon as possible. Additionally, consider implementing additional security measures, such as web application firewalls (WAFs) or intrusion detection systems (IDS), to help prevent future attacks.

As the cybersecurity landscape continues to evolve, it’s clear that site owners must remain vigilant against emerging threats like WP2Shell. By staying informed and taking proactive steps to secure their sites, they can reduce the risk of falling victim to these devastating attacks.


Source: SecurityWeek — 2026-07-20