WP2Shell Flaws Force Rapid WordPress Patch
A pair of newly identified vulnerabilities dubbed WP2Shell are being actively exploited in the wild, triggering forced site updates.
A pair of severe vulnerabilities, collectively referred to as WP2Shell, has triggered an urgent security response across the WordPress ecosystem. Attackers began targeting these flaws almost immediately after their existence was disclosed, forcing developers to push emergency updates to protect the platform's vast user base.
The Nature of the WP2Shell Attack
The vulnerabilities are tracked as CVE-2026-60137, a high-severity SQL injection bug, and CVE-2026-63030, which is classified as a critical arbitrary code execution flaw. Researchers at Searchlight Cyber, who discovered the bugs, found that they do not require any specific preconditions, meaning they can be weaponized against a default WordPress installation without the presence of third-party plugins.
By chaining these two vulnerabilities together, threat actors can achieve unauthenticated remote code execution. This allows an attacker to seize full control over an affected website. While the researchers behind the discovery have withheld specific technical details to mitigate the risk of further abuse, proof-of-concept exploits have already surfaced from other sources, leading to a rapid acceleration of in-the-wild exploitation attempts.
Emergency Patches and Security Measures
WordPress released official patches on Friday, corresponding to versions 6.9.5 and 7.0.2. Recognizing the gravity of the situation, the project team took the unusual step of enabling forced auto-updates for all sites running the vulnerable software versions. Additionally, firms such as Cloudflare have deployed rules to detect exploitation to provide a protective layer for users who have not yet updated their installations.
- WordPress versions 6.9.0 through 6.9.4 are affected.
- WordPress versions 7.0.0 through 7.0.1 are affected.
- Exploitation attempts were observed in honeypots over the weekend.
The Collapsing Window of Exposure
Security firms including Patchstack, Hexastrike, and WatchTowr have all confirmed the active exploitation of these vulnerabilities. The speed at which threat actors have moved has drawn concern from security leaders regarding the changing dynamics of vulnerability research and weaponization.
“This is also the latest example in a clear trend of vulnerabilities being surfaced by AI-assisted tooling, representing a significant shift in both how our industry finds these issues and how quickly attackers weaponize them. We saw PoCs appear within hours of disclosure, where historically that would have taken 24 hours or more. The window between disclosure and exploitation has collapsed, and WordPress is simply today’s reminder of it.”
— Benjamin Harris, CEO and founder of WatchTowr
Implications for Website Security
The rapid weaponization of WP2Shell highlights an intensifying challenge for administrators. The gap between a vulnerability’s public disclosure and its active exploitation by attackers is shrinking, leaving little room for manual remediation. For organizations relying on WordPress, the reliance on automated updates has moved from a convenience to a critical security necessity. In instances where auto-updates fail or are disabled, the time window for defensive action is now measured in hours rather than days, potentially leaving a significant number of unpatched websites vulnerable to complete takeover.
Sources
- SecurityWeek Original source
- patches Also reporting
- rules to detect exploitation Also reporting
- Patchstack Also reporting
Continue Reading
HAProxy Trojans Hide in South Korean Load Balancers
A Linux toolkit compiled into HAProxy binaries intercepts traffic for two South Korean firms, likely via state actors.
Chrome V8 Zero-Day Under Attack Gets Emergency Patch
Google patches a high-severity type confusion bug in V8 that has been exploited in the wild, the sixth zero-day fixed this year.
Texas, Florida Curb License Plate Surveillance
Texas and Florida are dialing back automated license plate reader use, signaling a shift in surveillance policy.