Advertisement
SecurityConfirmed

WP2Shell Flaws Force Rapid WordPress Patch

A pair of newly identified vulnerabilities dubbed WP2Shell are being actively exploited in the wild, triggering forced site updates.

··18 hours ago·2 min read
red padlock on black computer keyboard
Photo by FlyD on Unsplash
Advertisement

A pair of severe vulnerabilities, collectively referred to as WP2Shell, has triggered an urgent security response across the WordPress ecosystem. Attackers began targeting these flaws almost immediately after their existence was disclosed, forcing developers to push emergency updates to protect the platform's vast user base.

The Nature of the WP2Shell Attack

The vulnerabilities are tracked as CVE-2026-60137, a high-severity SQL injection bug, and CVE-2026-63030, which is classified as a critical arbitrary code execution flaw. Researchers at Searchlight Cyber, who discovered the bugs, found that they do not require any specific preconditions, meaning they can be weaponized against a default WordPress installation without the presence of third-party plugins.

By chaining these two vulnerabilities together, threat actors can achieve unauthenticated remote code execution. This allows an attacker to seize full control over an affected website. While the researchers behind the discovery have withheld specific technical details to mitigate the risk of further abuse, proof-of-concept exploits have already surfaced from other sources, leading to a rapid acceleration of in-the-wild exploitation attempts.

Emergency Patches and Security Measures

WordPress released official patches on Friday, corresponding to versions 6.9.5 and 7.0.2. Recognizing the gravity of the situation, the project team took the unusual step of enabling forced auto-updates for all sites running the vulnerable software versions. Additionally, firms such as Cloudflare have deployed rules to detect exploitation to provide a protective layer for users who have not yet updated their installations.

  • WordPress versions 6.9.0 through 6.9.4 are affected.
  • WordPress versions 7.0.0 through 7.0.1 are affected.
  • Exploitation attempts were observed in honeypots over the weekend.

The Collapsing Window of Exposure

Security firms including Patchstack, Hexastrike, and WatchTowr have all confirmed the active exploitation of these vulnerabilities. The speed at which threat actors have moved has drawn concern from security leaders regarding the changing dynamics of vulnerability research and weaponization.

“This is also the latest example in a clear trend of vulnerabilities being surfaced by AI-assisted tooling, representing a significant shift in both how our industry finds these issues and how quickly attackers weaponize them. We saw PoCs appear within hours of disclosure, where historically that would have taken 24 hours or more. The window between disclosure and exploitation has collapsed, and WordPress is simply today’s reminder of it.”

— Benjamin Harris, CEO and founder of WatchTowr

Implications for Website Security

The rapid weaponization of WP2Shell highlights an intensifying challenge for administrators. The gap between a vulnerability’s public disclosure and its active exploitation by attackers is shrinking, leaving little room for manual remediation. For organizations relying on WordPress, the reliance on automated updates has moved from a convenience to a critical security necessity. In instances where auto-updates fail or are disabled, the time window for defensive action is now measured in hours rather than days, potentially leaving a significant number of unpatched websites vulnerable to complete takeover.

#wordpress#vulnerability#cve-2026-60137#cve-2026-63030#cybersecurity

Xploitwire Editorial Team

Xploitwire Newsroom

This article's narrative text was drafted by AI (Google Gemini) from the sources listed above, and passed through our automated fact-check gate before publication. It has not been individually reviewed by a human editor prior to going live. Our AI Policy →

← Back to all stories
Advertisement