Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical WordPress RCE Vulnerability Discovered by AI

Critical WordPress RCE Vulnerability Discovered by AI

Posted on July 20, 2026 By CWS

A newly discovered critical remote code execution (RCE) vulnerability, named ‘wp2shell’, has been identified in WordPress Core. This flaw exposes over 500 million websites to potential takeovers by unauthenticated attackers. The vulnerability combines two distinct issues: a REST API batch-route confusion (CVE-2026-63030) and a SQL injection in the WP_Query class (CVE-2026-60137).

Unprecedented Vulnerability in WordPress

WordPress, the content management system powering approximately 43% of the web, is the subject of this significant security threat. Unlike typical vulnerabilities, wp2shell requires no specific conditions or user interaction. Any attacker with network access to a susceptible WordPress site can exploit this flaw.

This vulnerability was uncovered by Adam Kues from Searchlight Cyber’s Assetnote team using an AI model powered by OpenAI’s GPT-5.6 Sol Ultra. The AI identified the vulnerability through code analysis without consulting external data sources.

Technical Details of the Exploit

The wp2shell vulnerability involves two main components. The first is a desynchronization bug in the WordPress REST API batch endpoint, which disrupts validation and execution processes. This flaw is rated with a CVSS v3.1 score of 7.5, classified under CWE-436.

The second component is a SQL injection vulnerability in the WP_Query class. This allows attackers to bypass normal input validation, leading to potential SQL payloads being executed. This issue is classified as CWE-89 and carries a critical CVSS v3.1 score of 9.1.

By exploiting these vulnerabilities, attackers can escalate from SQL injection to full RCE, enabling them to create rogue administrator accounts and execute arbitrary code on the server.

Response and Mitigation

WordPress released emergency updates on July 17, 2026, to address these vulnerabilities. Automated updates were enabled for affected versions, though manual verification is advised to ensure protection. Versions prior to 6.9.0 are unaffected by the full RCE chain, while updates to 6.8.6, 6.9.5, and 7.0.2 are recommended for protection.

Administrators are urged to use tools such as wp2shell[.]com to assess their site’s vulnerability status. If updating immediately is not possible, blocking specific REST API routes at the web server level is advised as a temporary measure.

Implications for the Future of Cybersecurity

This discovery highlights the growing role of AI in cybersecurity research. With only a $25 compute cost, AI identified vulnerabilities that could potentially be valued at up to $500,000 in exploit markets. This could signal a shift in how vulnerabilities are discovered and addressed, emphasizing the importance of integrating AI into cybersecurity strategies.

As AI models take on more technical tasks, human researchers may focus on guiding AI efforts, selecting targets, and developing strategic research approaches, thereby transforming the landscape of vulnerability research.

Cyber Security News Tags:AI discovery, AI in cybersecurity, CVE-2026-60137, CVE-2026-63030, Cybersecurity, Exploit, RCE vulnerability, REST API, security update, site protection, SQL injection, vulnerability patch, web development, website security, WordPress

Post navigation

Previous Post: AI-Driven Phishing Toolkit Uncovered in WebDAV Campaign
Next Post: New Malware Exploits Microsoft 365 Calendars for Covert Commands

Related Posts

Free Decryptor Released for AI-Assisted FunkSec Ransomware Free Decryptor Released for AI-Assisted FunkSec Ransomware Cyber Security News
US Executives Admit Guilt in Tech Support Fraud Case US Executives Admit Guilt in Tech Support Fraud Case Cyber Security News
Adobe’s August 2025 Patch Tuesday Adobe’s August 2025 Patch Tuesday Cyber Security News
New Exploit for SAP 0-Day Vulnerability Allegedly Released in the Wild by ShinyHunters Hackers New Exploit for SAP 0-Day Vulnerability Allegedly Released in the Wild by ShinyHunters Hackers Cyber Security News
Researchers Bypassed Web Application Firewall With JS Injection with Parameter Pollution Researchers Bypassed Web Application Firewall With JS Injection with Parameter Pollution Cyber Security News
APT37 Hackers Weaponizes JPEG Files to Attack Windows System Leveraging “mspaint.exe” File APT37 Hackers Weaponizes JPEG Files to Attack Windows System Leveraging “mspaint.exe” File Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cyberattack Turns Telegram Bots Into Covert Control System
  • Furtex: Advanced Linux Toolkit for Security Experts
  • Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks
  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cyberattack Turns Telegram Bots Into Covert Control System
  • Furtex: Advanced Linux Toolkit for Security Experts
  • Critical PAN-OS Flaw Leads to Qilin Ransomware Attacks
  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark