Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical WordPress Flaws WP2Shell Actively Exploited

Critical WordPress Flaws WP2Shell Actively Exploited

Posted on July 20, 2026 By CWS

Two recently patched WordPress vulnerabilities, known as WP2Shell, have become the target of active exploitation. These vulnerabilities, identified as CVE-2026-60137 and CVE-2026-63030, started being attacked shortly after their discovery.

Details of the WP2Shell Vulnerabilities

Researchers from Searchlight Cyber have identified that WordPress versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 are susceptible to these flaws. These vulnerabilities can be exploited by anonymous users without any prerequisites, according to the security firm’s analysis.

Patches for these vulnerabilities were announced by WordPress with the release of versions 6.9.5 and 7.0.2. WordPress has enabled forced updates through their auto-update system to protect sites running impacted versions.

Industry Response and Mitigation Efforts

Cloudflare has implemented rules to detect and prevent exploitation for users who have not yet patched their systems. CVE-2026-60137 is classified as a high-severity SQL injection bug, while CVE-2026-63030 is a critical arbitrary code execution vulnerability. These issues, when combined, allow attackers to execute remote code without authentication.

Although Searchlight Cyber has withheld specific details to avoid misuse, proof-of-concept exploits have surfaced from other sources, highlighting the urgency for protective measures.

Impact and Expert Opinions

The active exploitation of WP2Shell has been confirmed by several cybersecurity entities, including Patchstack and Hexastrike. Hexastrike reported observing attack attempts in their honeypots and has been involved in responding to various incidents.

Benjamin Harris, CEO of WatchTowr, expressed concern over the widespread impact due to the extensive use of WordPress globally. He noted the rapid pace at which these vulnerabilities have been weaponized, facilitated by AI-assisted tools, which has drastically reduced the time between disclosure and exploitation.

This situation underscores a growing trend where vulnerabilities are identified and exploited faster than ever before, emphasizing the critical need for rapid patch management and robust security measures in the WordPress ecosystem.

Security Week News Tags:auto-update, Cloudflare, CVE-2026-60137, CVE-2026-63030, Cybersecurity, Hexastrike, patch management, Patchstack, remote code execution, Searchlight Cyber, SQL injection, Vulnerabilities, WatchTowr, WordPress, wp2shell

Post navigation

Previous Post: Hugging Face AI Platform Breached by Autonomous AI
Next Post: Malicious RubyGems Packages Threaten Developer Security

Related Posts

Cisco Reports 2026’s Seventh SD-WAN Zero-Day Flaw Cisco Reports 2026’s Seventh SD-WAN Zero-Day Flaw Security Week News
Developer Who Hacked Former Employer’s Systems Sentenced to Prison Developer Who Hacked Former Employer’s Systems Sentenced to Prison Security Week News
Webinar Today: The Future of Industrial Network Security Webinar Today: The Future of Industrial Network Security Security Week News
How Software Development Teams Can Securely and Ethically Deploy AI Tools How Software Development Teams Can Securely and Ethically Deploy AI Tools Security Week News
US Shuts Down Crypto Exchange E-Note, Charges Russian Administrator US Shuts Down Crypto Exchange E-Note, Charges Russian Administrator Security Week News
Flare Raises  Million for Threat Exposure Management Platform Flare Raises $30 Million for Threat Exposure Management Platform Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently
  • Microsoft to End OneDrive Sync Support for Windows 10
  • Paidwork Data Breach Exposes Millions of Users’ Data
  • FakeGit Exploits GitHub to Distribute SmartLoader Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft’s KB5121767 Update Resolves Dell USB-C Issues
  • LG Monitor Software May Install Adware Silently
  • Microsoft to End OneDrive Sync Support for Windows 10
  • Paidwork Data Breach Exposes Millions of Users’ Data
  • FakeGit Exploits GitHub to Distribute SmartLoader Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark