news.mlab.sh
Back to the feed
threat-intel

WP2Shell WordPress Vulnerabilities Exploited in the Wild

High
Summary

Two recently patched WordPress vulnerabilities, WP2Shell (CVE-2026-60137 and CVE-2026-63030), are being actively exploited in the wild. Attackers are leveraging these flaws to gain remote code execution on WordPress sites, and the speed at which exploits are appearing highlights a concerning trend of accelerated vulnerability weaponization.

Two newly patched WordPress vulnerabilities, WP2Shell (CVE-2026-60137 and CVE-2026-63030), are being actively exploited in the wild. WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected. According to Searchlight Cyber, the attack requires no preconditions and can be exploited by an anonymous user on a stock WordPress installation without any plugins. WordPress announced patches on Friday with the release of versions 6.9.5 and 7.0.2, and the WordPress.org team enabled forced updates via the auto-update system for sites running affected versions.

Cloudflare has also rolled out rules to detect exploitation and protect customers whose installations were not immediately patched. CVE-2026-60137 is a high-severity SQL injection bug, and CVE-2026-63030 is a critical arbitrary code execution vulnerability. Chaining the two flaws enables an attacker to achieve unauthenticated remote code execution on affected WordPress websites.

Threat actors, including Hexastrike and WatchTowr, have confirmed in-the-wild exploitation attempts. Hexastrike reported seeing exploitation attempts in its honeypots over the weekend, and has assisted with incident response in several attacks. WatchTowr has also seen in-the-wild exploitation attempts.

“This is going to hurt,” Benjamin Harris, CEO and founder of WatchTowr, told SecurityWeek. “WordPress runs on hundreds of millions of websites globally. Some of those will be auto-patched by their hosting providers, but plenty will not, and that is where the damage will be done.” The rapid appearance of PoCs following disclosure highlights a shift in how vulnerabilities are discovered and weaponized, with attackers now exploiting them within hours of their release.

Related: Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data Related: 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown Related: Everest Forms Vulnerability Exploited to Hack WordPress Sites

Read the full article at SecurityWeek