Two recently patched WordPress vulnerabilities, known as WP2Shell, have become the target of active exploitation. These vulnerabilities, identified as CVE-2026-60137 and CVE-2026-63030, started being attacked shortly after their discovery.
Details of the WP2Shell Vulnerabilities
Researchers from Searchlight Cyber have identified that WordPress versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 are susceptible to these flaws. These vulnerabilities can be exploited by anonymous users without any prerequisites, according to the security firm’s analysis.
Patches for these vulnerabilities were announced by WordPress with the release of versions 6.9.5 and 7.0.2. WordPress has enabled forced updates through their auto-update system to protect sites running impacted versions.
Industry Response and Mitigation Efforts
Cloudflare has implemented rules to detect and prevent exploitation for users who have not yet patched their systems. CVE-2026-60137 is classified as a high-severity SQL injection bug, while CVE-2026-63030 is a critical arbitrary code execution vulnerability. These issues, when combined, allow attackers to execute remote code without authentication.
Although Searchlight Cyber has withheld specific details to avoid misuse, proof-of-concept exploits have surfaced from other sources, highlighting the urgency for protective measures.
Impact and Expert Opinions
The active exploitation of WP2Shell has been confirmed by several cybersecurity entities, including Patchstack and Hexastrike. Hexastrike reported observing attack attempts in their honeypots and has been involved in responding to various incidents.
Benjamin Harris, CEO of WatchTowr, expressed concern over the widespread impact due to the extensive use of WordPress globally. He noted the rapid pace at which these vulnerabilities have been weaponized, facilitated by AI-assisted tools, which has drastically reduced the time between disclosure and exploitation.
This situation underscores a growing trend where vulnerabilities are identified and exploited faster than ever before, emphasizing the critical need for rapid patch management and robust security measures in the WordPress ecosystem.
