WP2Shell Flaws Force Rapid WordPress Patch
A pair of newly identified vulnerabilities dubbed WP2Shell are being actively exploited in the wild, triggering forced site updates.
A pair of severe vulnerabilities, collectively referred to as WP2Shell, has triggered an urgent security response across the WordPress ecosystem. Attackers began targeting these flaws almost immediately after their existence was disclosed, forcing developers to push emergency updates to protect the platform's vast user base.
The Nature of the WP2Shell Attack
The vulnerabilities are tracked as CVE-2026-60137, a high-severity SQL injection bug, and CVE-2026-63030, which is classified as a critical arbitrary code execution flaw. Researchers at Searchlight Cyber, who discovered the bugs, found that they do not require any specific preconditions, meaning they can be weaponized against a default WordPress installation without the presence of third-party plugins.
By chaining these two vulnerabilities together, threat actors can achieve unauthenticated remote code execution. This allows an attacker to seize full control over an affected website. While the researchers behind the discovery have withheld specific technical details to mitigate the risk of further abuse, proof-of-concept exploits have already surfaced from other sources, leading to a rapid acceleration of in-the-wild exploitation attempts.
Emergency Patches and Security Measures
WordPress released official patches on Friday, corresponding to versions 6.9.5 and 7.0.2. Recognizing the gravity of the situation, the project team took the unusual step of enabling forced auto-updates for all sites running the vulnerable software versions. Additionally, firms such as Cloudflare have deployed rules to detect exploitation to provide a protective layer for users who have not yet updated their installations.
- WordPress versions 6.9.0 through 6.9.4 are affected.
- WordPress versions 7.0.0 through 7.0.1 are affected.
- Exploitation attempts were observed in honeypots over the weekend.
The Collapsing Window of Exposure
Security firms including Patchstack, Hexastrike, and WatchTowr have all confirmed the active exploitation of these vulnerabilities. The speed at which threat actors have moved has drawn concern from security leaders regarding the changing dynamics of vulnerability research and weaponization.
“This is also the latest example in a clear trend of vulnerabilities being surfaced by AI-assisted tooling, representing a significant shift in both how our industry finds these issues and how quickly attackers weaponize them. We saw PoCs appear within hours of disclosure, where historically that would have taken 24 hours or more. The window between disclosure and exploitation has collapsed, and WordPress is simply today’s reminder of it.”
— Benjamin Harris, CEO and founder of WatchTowr
Implications for Website Security
The rapid weaponization of WP2Shell highlights an intensifying challenge for administrators. The gap between a vulnerability’s public disclosure and its active exploitation by attackers is shrinking, leaving little room for manual remediation. For organizations relying on WordPress, the reliance on automated updates has moved from a convenience to a critical security necessity. In instances where auto-updates fail or are disabled, the time window for defensive action is now measured in hours rather than days, potentially leaving a significant number of unpatched websites vulnerable to complete takeover.
Continue Reading
LightRAG Critical CORS Flaw Enables Data Theft
A critical vulnerability in LightRAG allows unauthorized cross-origin requests, potentially exposing sensitive documents and knowledge graph data.
LightRAG Critical Auth Bypass Vulnerability
A hardcoded secret in LightRAG allows unauthenticated attackers to bypass API key protections and gain full control over document operations.
Critical DoS Flaw Found in npm tar Package
A severe vulnerability in the node-tar library allows attackers to crash servers and exhaust storage through maliciously crafted archive files.
Sources
- WP2Shell
- patches
- rules to detect exploitation
- Patchstack
- Attackers Exploit Gravity SMTP Plugin Flaw to Harvest Valuable WordPress Data
- 15,000 WordPress Websites Cleaned Up in SocGholish Botnet Takedown
- Everest Forms Vulnerability Exploited to Hack WordPress Sites
- Eduard Kovacs
- Two Scattered Spider Hackers Sentenced to Jail in UK
- ‘ClickLock Stealer’ Bypasses macOS Security With Social Engineering, Process Killing
- China’s Top Cybersecurity Firms Hit by Mounting Military Procurement Bans
- Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities