Researchers Alert: Hackers Taking Advantage of Recently Fixed WordPress Vulnerabilities

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Cybercriminals are actively exploiting two recently patched vulnerabilities in WordPress, thereby endangering millions of websites that have not yet installed the vital security updates.

This alarming situation has arisen with the emergence of an attack vector known as WP2Shell, which ingeniously combines two distinct WordPress Core vulnerabilities to enable pre-authentication remote code execution. This functionality permits adversaries to execute malicious code without requiring prior login credentials.

The seriousness of these vulnerabilities prompted WordPress to release updated versions and to enable automatic security updates.

However, cybersecurity experts caution that millions of websites remain susceptible, with security firm WatchTowr reporting that it has already observed real-world exploitation of these flaws, as noted by BleepingComputer.

This places the onus squarely on website owners who have yet to implement the necessary updates, serving as a stark reminder of the imperative to prioritize security enhancements.

Two Vulnerabilities: A Single Catastrophic Attack

Individually, the vulnerabilities identified as CVE-2026-63030 and CVE-2026-60137 can be exploited separately. However, when chained, they empower an attacker to fully compromise a website without the need for authentication.

According to BleepingComputer, both vulnerabilities were unearthed by Adam Kues, a researcher at Searchlight Cyber. He aptly named the attack WP2Shell due to its capability to facilitate the execution of arbitrary shell commands on compromised websites.

CVE-2026-63030, categorized as critical, exposes a flaw in WordPress’s Batch REST API, leading to the misinterpretation of certain grouped API requests. This confusion can result in incorrect security checks, allowing malicious requests to infiltrate secured areas of the system.

Conversely, CVE-2026-60137 carries a moderate risk and can lead to SQL injection vulnerabilities.

As reported by TechCrunch, an estimated 90 million websites remain directly exposed to this exploit chain, while over 400 million sites are believed to be operating on WordPress versions that fall within the susceptible range. Although not all these sites are necessarily at risk, the figures underscore the potential expanse of the threat.

A Rare Kind of WordPress Attack

What makes the WP2Shell attack particularly unsettling is its focus on WordPress Core rather than third-party plugins.

Most notable attacks associated with WordPress have typically stemmed from plugins utilized by site owners. In contrast, CVE-2026-63030 and CVE-2026-60137 affect the underlying WordPress software itself. Consequently, websites operating with a clean, default WordPress installation could also find themselves vulnerable.

Why Patching Quickly Matters

A broader lesson to be gleaned from this incident is that threat actors have become adept at exploiting security updates to target users who are still running outdated software. This serves as a compelling reminder that software updates must be regarded as a continuous necessity.

Despite the availability of a patch and the activation of automatic updates by WordPress, ongoing reports of live exploitation indicate that many site owners failed to implement the updates in a timely manner.

This suggests that numerous affected sites either neglected to install the latest updates or were not configured to receive automatic security patches. Therefore, if your website operates on WordPress, immediate software updates are strongly advised.

It is recommended to enable automatic updates whenever feasible or, if that is not an option, to establish monitoring systems that alert you upon the release of a new update.

While organizations running critical software might prefer to vet updates to ensure they do not disrupt existing systems, applying a test update in a non-production environment can serve as a prudent verification step.

The rationale is straightforward: cybersecurity has evolved into a race for execution speed, a sentiment echoed by even companies like Microsoft, which now advocate for customers to implement updates within a span of three days. Ultimately, the swiftest party frequently emerges victorious in this arena.

Modern Microsoft office building with large logo, glass facade, and people walking outside in an urban business setting.

As attackers increasingly weaponize newly disclosed vulnerabilities within mere days—if not hours—of patch availability, expeditious patch management remains one of the most potent defenses available to organizations seeking to mitigate compromises.

Other News: Microsoft is reportedly in the process of developing an AI-driven security tool that could potentially surpass Anthropic’s Mythos by autonomously identifying and rectifying software vulnerabilities at a reduced cost for enterprise customers.

Source link: Techrepublic.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading