Hackers Exploit Newly Patched WordPress Vulnerabilities

News Room

Hackers are already exploiting two newly patched WordPress vulnerabilities, exposing millions of websites that have yet to install the latest security updates to potential takeover.

The attack chain, dubbed WP2Shell, combines two WordPress Core vulnerabilities to achieve pre-authentication remote code execution, allowing attackers to run malicious code without first logging in.

The vulnerabilities are so severe that WordPress has released patched versions and enabled automatic security updates. Yet security researchers are warning that millions of the platform websites remain vulnerable, with Security firm WatchTowr saying ā€œit has already seen in-the-wild exploitationā€ of the vulnerabilities, according to BleepingComputer.

That leaves the responsibility now on the shoulders of site owners who have yet to update their websites and, at the same time, serves as a reminder to all of the importance of treating security updates as a priority.

Two vulnerabilities: a single catastrophic attack

Alone, each vulnerability tracked as CVE-2026-63030 and CVE-2026-60137 can be exploited individually. Chained together, both can allow an attacker to fully compromise a website without ever needing to get authenticated.

According to BleepingComputer, both vulnerabilities were discovered by Adam Kues, a security researcher at Searchlight Cyber. He dubbed the attack WP2Shell, a name derived from its ability to allow an attacker to execute arbitrary shell commands on a vulnerable website.

CVE-2026-63030, rated critical, is a flaw in WordPress’s Batch REST API that can cause the software to misinterpret certain grouped API requests. Because of this confusion, WordPress may apply the wrong security checks, allowing specially crafted requests to reach parts of the system they shouldn’t.

CVE-2026-60137, on the other hand, has a moderate rating and can cause an SQL injection.

Quoting cybersecurity consultant Daniel Card, TechCrunch estimates that roughly 90 million websites remain directly exposed to the exploit chain, while more than 400 million sites are believed to be running WordPress versions within the affected release ranges. Not all of those sites are necessarily vulnerable, but the figures illustrate the attack’s potentially broad reach.

A rare kind of WordPress attack

What makes WP2Shell particularly concerning is that it targets WordPress Core rather than a third-party plugin.

Most WordPress-based attacks making headlines have usually been caused by plugins that site owners use on their websites. However, CVE-2026-63030 and CVE-2026-60137 affect the WordPress software itself.

That means even websites running a clean, default WordPress installation could be vulnerable.

Must-read security coverage

Why patching quickly matters

A bigger lesson from this isn’t related to WordPress. It is that threat actors have learned to capitalize on security updates released to exploit users still running unpatched software. For everyone, this indicates that software updates should no longer be treated as a periodic activity.

Despite a patch existing and WordPress enabling automatic updates, reports of live exploitation suggest that many site owners didn’t catch it, suggesting that many affected sites either had not yet installed the updates or were not receiving automatic security patches. If your website runs WordPress, the platform urges you to update your software without delay.

Our recommendation is to set up auto-updates where necessary, or, when that’s impossible, set up monitoring systems that alert you when an update becomes available. Those who run critical software in production may understandably want to ensure an update won’t break their systems, but, if possible, a test update can be applied on a non-production system to validate its quality.

The reason is simple: cybersecurity has become a battle over execution speed, and even companies like Microsoft have begun urging customers to update their devices within three days because, at the end of the day, the fastest party often wins.

As attackers increasingly weaponize newly disclosed vulnerabilities within days—or even hours—of patches becoming available, rapid patch management has become one of the most effective defenses organizations have against compromise.

Other News: Microsoft is reportedly developing an AI-powered security tool that could undercut Anthropic’s Mythos by automatically finding and fixing software vulnerabilities at a lower cost for enterprise customers.

Read the full article here

Share This Article
Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *