Rising Exploitation of WordPress wp2shell as Public Exploit Triggers Widespread Scanning

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Critical Vulnerabilities in WordPress Exploited for Remote Code Execution

Recent reports indicate that malicious actors are actively exploiting two severe vulnerabilities in WordPress. When combined, these flaws facilitate unauthenticated remote code execution (RCE) and can lead to the full compromise of vulnerable websites.

The vulnerabilities in question, identified as CVE-2026-63030 and CVE-2026-60137, have been broadly referred to as wp2shell.

“By early Saturday morning (UTC), we observed significant exploitation attempts, starting with publicly available exploit code being used to exfiltrate hashed credentials.

Subsequent remote code execution was initiated once additional details surfaced,” remarked Jake Knott, principal security researcher at watchTowr, in a statement to The Hacker News.

“From our perspective, encompassing a global client base, the ramifications of this vulnerability are extensive, affecting organizations across various sectors,” Knott added.

Telemetry data from KEVIntel reveals that exploitation efforts have been linked to 13 distinct IP addresses across Switzerland, Germany, the U.K., Indonesia, Lithuania, the Netherlands, and Singapore.

Ryan Dewhurst, the founder and CEO of KEVIntel, noted to The Hacker News that exploitation activities have transitioned from targeting WordPress-specific sensors to encompassing broad Internet scanning, with requests aligning with published proof-of-concept (PoC) exploits.

“Attackers have employed various SQL injection techniques, including blind, UNION-based, and Boolean-based payloads,” Dewhurst explained.

“Our testing indicated that AI-assisted analysis made it exceedingly easy to reproduce the vulnerability and create a functioning proof of concept. This significantly diminishes the technical barrier for generating exploit code once pertinent vulnerability details are released.”

The exploit chain, identified by Searchlight Cyber, utilized OpenAI GPT 5.6 and uncovered fundamental vulnerabilities in over ten hours.

This enables unauthenticated attackers to execute remote code on default WordPress installations across any version released since December 2025. Technical specifics have been withheld due to the severity of the situation.

“This attack incurs no prerequisites and can be executed by an anonymous user on a stock WordPress installation devoid of plugins,” Searchlight Cyber stated.

According to Cloudflare, CVE-2026-63030 facilitates unauthenticated remote code execution (RCE) only when a persistent object cache is absent.

The SQL injection vulnerability (CVE-2026-60137) has been detected from version 6.8 onwards, while the RCE impacts versions starting from 6.9.

“This exploit utilizes a dual-vulnerability chain for achieving unauthenticated code execution on a standard WordPress installation with a solitary HTTP request,” explained Ben Marr, a security engineer at Intruder.

“CVE-2026-63030 serves as the entry point—characterized by a route confusion error in the REST API batch endpoint that circumvents authentication, permitting an attacker to engage internal handlers devoid of permission checks.”

“The flaw stems from inadequate sanitization of the ‘author__not_in’ parameter within ‘WP_Query,’ particularly when untrusted data is provided by a plugin or theme.

This vulnerability enables crafted input to manipulate a database query, resulting in potential unauthorized access or data manipulation,” he added.

Data sourced from Google-owned Wiz indicates that 60% of organizations utilizing WordPress had at least one vulnerable instance at the time these CVEs were disclosed, with 25% exposing a susceptible server to the Internet. However, these figures have since decreased as organizations have applied necessary fixes.

Post-exploitation activities observed following the abuse of these two vulnerabilities include:

  • Deployment of malicious plugins
  • Enumeration of users and extraction of admin usernames and email addresses
  • Execution of local file inclusion (LFI) attacks targeting database credentials and authentication keys for exfiltration
  • Unauthorized access to the admin panel
  • Installation of a rudimentary PHP web shell facilitating remote code execution

“We have also recorded high-volume scanning activities without subsequent exploitation, suggesting opportunistic mass-scanning campaigns seeking vulnerable targets alongside legitimate security scanning efforts,” said Wiz researchers Shahar Dorfman and Gili Tikochinski.

“While we have not yet observed lateral movement or data exfiltration, monitoring and investigation remain ongoing.”

Additionally, a 150 KB web shell has been detected, masquerading as a legitimate WordPress security plugin named CMSmap.

This shell functions as a “full-featured attack platform,” enabling file management, database access, port scanning, batch code injection, and various privilege escalation techniques, including MySQL UDF exploitation.

WatchTowr reports that attackers have commenced widespread, indiscriminate scanning following the release of public exploits, with honeypots detecting “tens of thousands of exploitation attempts.”

Over 100 backdoor administrator accounts have reportedly been established following the exploitation, allowing attackers to introduce fake WordPress plugins to execute code or retrieve secondary tools for further system compromise.

In certain instances, threat actors have attempted to install Overlord RAT, a Golang-based remote access Trojan.

Security professionals are advised to meticulously inspect their WordPress installations for new administrator accounts, malicious plugins, or other suspicious files, irrespective of whether they have been patched, to thoroughly eradicate the threat.

Dewhurst stated that the potential blast radius was mitigated by existing defensive measures. “WordPress has incorporated automatic background updates for security releases for several years, and some infrastructure providers received advanced alerts, enabling rapid deployment of virtual patches,” he noted.

“These actions curtailed the exposure period for sites that updated automatically or were safeguarded by relevant WAF rules.”

Nonetheless, sites with disabled automatic updates, or those deemed unsupported or unsuccessful, may still be vulnerable.

Given the widespread deployment of WordPress across the web, a considerable number of installations may yet be unpatched.

white and blue printer paper

Operators of sites that remained susceptible post-public release of exploit code should update promptly and review their systems for indicators of compromise, rather than assuming that mere patch application suffices.

Source link: Thehackernews.com.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading