WP2Shell: Two WordPress Flaws Are Being Exploited Right Now, and Millions of Sites Are at Risk

A pair of newly patched security holes in WordPress are already being used in live attacks. No login required. No special setup needed. Just a vulnerable website.

ThreatVectr Newsdesk· 3 min read
Macro photograph of tangled fiber optic cables glowing in deep blue and green light against a dark server room background, sharp focus on the glass fiber tips w
Share

Key points

  • Two WordPress security flaws, tracked as CVE-2026-60137 and CVE-2026-63030, are being actively exploited as of this weekend.
  • Affected WordPress versions span 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, with patches released Friday in versions 6.9.5 and 7.0.2.
  • An attacker needs no account and no special configuration to exploit either flaw on a standard WordPress site.
  • WordPress has forced automatic updates to patched versions for sites that still run the vulnerable software.
  • Working exploit code appeared publicly within hours of the vulnerabilities being disclosed, collapsing the usual window between discovery and attack.

Two newly patched security flaws in WordPress, the software that powers a significant share of the world's websites, are being used in real attacks right now. Researchers have named the pair "WP2Shell." The name is shorthand for what the flaws ultimately let an attacker do: gain shell access, meaning full remote control over a web server.

The flaws were discovered by Searchlight Cyber and are officially catalogued as CVE-2026-60137 and CVE-2026-63030. The first is a SQL injection bug, where a criminal sends specially crafted text to a site's database to extract or manipulate data. The second is an arbitrary code execution vulnerability, meaning an attacker can run any software they choose on the target server. Use both together and the result is unauthenticated remote code execution: a complete takeover, no password required.

How did the hackers get in?

They did not need to "get in" through stolen credentials. The attack works against a plain, out-of-the-box WordPress installation with no added plugins, on any site still running versions 6.9.0 to 6.9.4 or 7.0.0 to 7.0.1. Anyone on the internet can attempt it anonymously.

Searchlight Cyber withheld technical details to limit abuse. That caution came too late. Working exploit code appeared publicly within hours of disclosure, first reported by SecurityWeek. Historically, criminals needed a day or more to reverse-engineer a patch and build a working attack. That window has collapsed.

WatchTowr CEO Benjamin Harris put it plainly: "WordPress runs on hundreds of millions of websites globally. Some of those will be auto-patched by their hosting providers, but plenty will not, and that is where the damage will be done."

Security firms Patchstack, Hexastrike, and WatchTowr have all confirmed live exploitation attempts. Hexastrike says it has already helped clean up several compromised sites since Sunday.

The good news is concrete. WordPress pushed patches on Friday, releasing versions 6.9.5 and 7.0.2. Because the flaw is so serious, WordPress also switched on forced automatic updates, pushing the fix to vulnerable sites without waiting for site owners to act. Web infrastructure company Cloudflare has deployed detection rules to block known attack patterns for its customers.

If you run a WordPress site, log in today and confirm your version number is 6.9.5 or 7.0.2. If your hosting provider manages updates, check that automatic updates are enabled. If your site was running a vulnerable version over the past several days, treat it as potentially compromised and ask your host or a security professional to review it.

Ordinary visitors to affected sites could have had their personal data exposed or been redirected to malicious pages without any warning. If a site you use recently behaved oddly, such as unexpected redirects or strange pop-ups, that is worth reporting to the site owner.

© 2026 Threat Vectr