Back to Feed
VulnerabilitiesJul 20, 2026

WP2Shell WordPress Vulnerabilities Exploited in the Wild

WordPress vulnerabilities CVE-2026-60137 and CVE-2026-63030 exploited in the wild within hours of disclosure.

Summary

Two critical WordPress vulnerabilities tracked as WP2Shell (CVE-2026-60137 and CVE-2026-63030) are being actively exploited in the wild shortly after disclosure. The flaws affect WordPress versions 6.9.0–6.9.4 and 7.0.0–7.0.1, allowing unauthenticated remote code execution when chained together. WordPress released patches (versions 6.9.5 and 7.0.2) and enabled forced auto-updates due to severity.

Full text

Two newly patched WordPress vulnerabilities are being exploited in the wild, with attacks beginning shortly after they came to light. The vulnerabilities have been dubbed WP2Shell and they are officially tracked as CVE-2026-60137 and CVE-2026-63030. According to Searchlight Cyber, whose researchers discovered the flaws, WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected. “The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins,” the security firm warned. WordPress announced patches on Friday with the release of versions 6.9.5 and 7.0.2. “Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions,” WordPress developers said. Advertisement. Scroll to continue reading. Cloudflare has also rolled out rules to detect exploitation and protect customers whose installations were not immediately patched. CVE-2026-60137 is a high-severity SQL injection bug and CVE-2026-63030 is a critical arbitrary code execution vulnerability. Chaining the two flaws enables an attacker to achieve unauthenticated remote code execution on affected WordPress websites. Threat actors can exploit these vulnerabilities to take control of targeted sites. While Searchlight Cyber has not made public any details to prevent abuse, PoC exploits have already been made public by others. WP2Shell exploited in the wild The in-the-wild exploitation of the WP2Shell vulnerabilities has been confirmed by several cybersecurity firms. One of them is the WordPress security company Patchstack. Hexastrike started seeing exploitation attempts in its honeypots over the weekend, and on Sunday the company said it had already assisted with incident response in several attacks. Hexastrike has shared some recommendations for detecting and investigating intrusions. WatchTowr has also seen in-the-wild exploitation attempts. “This is going to hurt,” the company’s CEO and founder, Benjamin Harris, told SecurityWeek. “WordPress runs on hundreds of millions of websites globally. Some of those will be auto-patched by their hosting providers, but plenty will not, and that is where the damage will be done.” Harris added, “This is also the latest example in a clear trend of vulnerabilities being surfaced by AI-assisted tooling, representing a significant shift in both how our industry finds these issues and how quickly attackers weaponize them. We saw PoCs appear within hours of disclosure, where historically that would have taken 24 hours or more. The window between disclosure and exploitation has collapsed, and WordPress is simply today’s reminder of it.” Related: Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data Related: 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown Related: Everest Forms Vulnerability Exploited to Hack WordPress Sites Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Two Scattered Spider Hackers Sentenced to Jail in UK‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process KillingChina’s Top Cybersecurity Firms Hit by Mounting Military Procurement BansTrend Micro, Tanium, ESET and Tenable Patch Severe Product VulnerabilitiesUS Charges Russian Individuals and Firms for Running Cybercrime ServicesWhite House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination InitiativeICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, RockwellSonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits Latest News In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD BlueprintPodcast: Broken Governance, Agentic AI, and the MindStone Agent ExclusiveBeacon Security Raises $13 Million for Security Data PlatformIndustry Reactions to Pentagon Suspending CMMC Phase 2: Feedback FridayCyberattack Disrupts Operations of Japanese Frozen Food Giant NichireiRisk Ledger Raises $32 Million in Series B FundingFresh SharePoint Vulnerability Exploited Soon After DisclosureCoca-Cola Suspends US Fairlife Production Due to Ransomware Attack Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Why Email Security Keeps Failing (And What Has to Change) July 8, 2026 Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more. Register Virtual Event: 2026 Cloud Security Summit July 15, 2026 This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. Register People on the MoveJazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.AJ Shipley has been appointed Chief Product Officer at CrowdStrike.Brinqa has named Ron Dovich as Chief AI and Automation Officer, David Allen as CTO, Steve Biagioni as CFO, and James Walta as VP of Product.More People On The MoveExpert Insights Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. (Joshua Goldfarb) The AI Token Costs That Can Break Cybersecurity As cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-60137
  • cve — CVE-2026-63030

Entities

WordPress (product)WordPress.org (vendor)Searchlight Cyber (vendor)Cloudflare (vendor)Patchstack (vendor)WP2Shell (campaign)