Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical WordPress RCE Vulnerability Discovered by AI

Critical WordPress RCE Vulnerability Discovered by AI

Posted on July 20, 2026 By CWS

A newly discovered critical remote code execution (RCE) vulnerability, named ‘wp2shell’, has been identified in WordPress Core. This flaw exposes over 500 million websites to potential takeovers by unauthenticated attackers. The vulnerability combines two distinct issues: a REST API batch-route confusion (CVE-2026-63030) and a SQL injection in the WP_Query class (CVE-2026-60137).

Unprecedented Vulnerability in WordPress

WordPress, the content management system powering approximately 43% of the web, is the subject of this significant security threat. Unlike typical vulnerabilities, wp2shell requires no specific conditions or user interaction. Any attacker with network access to a susceptible WordPress site can exploit this flaw.

This vulnerability was uncovered by Adam Kues from Searchlight Cyber’s Assetnote team using an AI model powered by OpenAI’s GPT-5.6 Sol Ultra. The AI identified the vulnerability through code analysis without consulting external data sources.

Technical Details of the Exploit

The wp2shell vulnerability involves two main components. The first is a desynchronization bug in the WordPress REST API batch endpoint, which disrupts validation and execution processes. This flaw is rated with a CVSS v3.1 score of 7.5, classified under CWE-436.

The second component is a SQL injection vulnerability in the WP_Query class. This allows attackers to bypass normal input validation, leading to potential SQL payloads being executed. This issue is classified as CWE-89 and carries a critical CVSS v3.1 score of 9.1.

By exploiting these vulnerabilities, attackers can escalate from SQL injection to full RCE, enabling them to create rogue administrator accounts and execute arbitrary code on the server.

Response and Mitigation

WordPress released emergency updates on July 17, 2026, to address these vulnerabilities. Automated updates were enabled for affected versions, though manual verification is advised to ensure protection. Versions prior to 6.9.0 are unaffected by the full RCE chain, while updates to 6.8.6, 6.9.5, and 7.0.2 are recommended for protection.

Administrators are urged to use tools such as wp2shell[.]com to assess their site’s vulnerability status. If updating immediately is not possible, blocking specific REST API routes at the web server level is advised as a temporary measure.

Implications for the Future of Cybersecurity

This discovery highlights the growing role of AI in cybersecurity research. With only a $25 compute cost, AI identified vulnerabilities that could potentially be valued at up to $500,000 in exploit markets. This could signal a shift in how vulnerabilities are discovered and addressed, emphasizing the importance of integrating AI into cybersecurity strategies.

As AI models take on more technical tasks, human researchers may focus on guiding AI efforts, selecting targets, and developing strategic research approaches, thereby transforming the landscape of vulnerability research.

Cyber Security News Tags:AI discovery, AI in cybersecurity, CVE-2026-60137, CVE-2026-63030, Cybersecurity, Exploit, RCE vulnerability, REST API, security update, site protection, SQL injection, vulnerability patch, web development, website security, WordPress

Post navigation

Previous Post: AI-Driven Phishing Toolkit Uncovered in WebDAV Campaign
Next Post: New Malware Exploits Microsoft 365 Calendars for Covert Commands

Related Posts

Critical Vulnerabilities in Angular Extension Pose RCE Risk Critical Vulnerabilities in Angular Extension Pose RCE Risk Cyber Security News
Critical Google Gemini CLI Flaw Exposes Systems to Attack Critical Google Gemini CLI Flaw Exposes Systems to Attack Cyber Security News
Threat Actors Testing Modified and Highly Obfuscated Version of Shai Hulud Strain Threat Actors Testing Modified and Highly Obfuscated Version of Shai Hulud Strain Cyber Security News
5 Email Attacks SOCs Cannot Detect Without A Sandbox  5 Email Attacks SOCs Cannot Detect Without A Sandbox  Cyber Security News
Microsoft Investigation Copilot Issue On Processing Files  Microsoft Investigation Copilot Issue On Processing Files  Cyber Security News
CISA Adds Digiever Authorization Vulnerability to KEV List Following Active Exploitation CISA Adds Digiever Authorization Vulnerability to KEV List Following Active Exploitation Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C
  • SonicWall Flaws Exploited to Deploy Malware
  • Estée Lauder Faces Data Breach from Oracle Zero-Day Attack
  • Meta Awards $78,000 for Major Support Data Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C
  • SonicWall Flaws Exploited to Deploy Malware
  • Estée Lauder Faces Data Breach from Oracle Zero-Day Attack
  • Meta Awards $78,000 for Major Support Data Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark