WordPress has addressed two critical vulnerabilities, known collectively as 'wp2shell' and tracked as CVE-2026-60137 and CVE-2026-63030. These flaws enable unauthenticated remote code execution on installations of WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.
WordPress released versions 6.9.5 and 7.0.2 on July 17, 2026 to patch these vulnerabilities. The developer also enabled forced automatic updates for sites to secure installations promptly.
The vulnerabilities were exploited in the wild before patches were issued. Public proof-of-concept exploits surfaced quickly after the vulnerabilities were disclosed, complicating the situation for site administrators.
The vast number of affected sites, estimated to exceed 500 million, underscores the widespread impact and severity of these vulnerabilities. Cybersecurity firms reported ongoing exploitation attempts, including the installation of malicious plugins and webshells.
Security entities such as Cloudflare rapidly introduced Web Application Firewall (WAF) protections to guard against these exploits while administrators applied needed patches. These measures, though helpful, are not replacements for patching the core vulnerabilities.
The issue highlights the importance of timely updates and vigilant monitoring of WordPress installations to mitigate risks posed by such severe vulnerabilities.
Site administrators are strongly advised to confirm their WordPress installations are updated to at least versions 6.9.5 or 7.0.2. Additionally, leveraging WAF technologies, like those provided by Cloudflare, can provide an extra layer of security against such attacks.
Administrators should regularly monitor for updates and be proactive in applying them, given the critical nature and ongoing exploitation of the vulnerabilities.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Hackers are exploiting critical wp2shell vulnerabilities (CVE-2026-63030, CVE-2026-60137) in WordPress to install webshells and malicious plugins. This exploitation, leveraging the REST API's batch-processing feature, poses a significant threat as it allows attackers to execute code without authentication.
Two critical vulnerabilities in WordPress, codenamed wp2shell, enable remote code execution. Attackers exploit these flaws across multiple countries, compromising unprotected WordPress installations.
Cybersecurity firms report active exploitation of recently patched WordPress vulnerabilities affecting tens of millions of websites. With versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 still widely in use, immediate updates are crucial to mitigate risks.
A severe remote code execution vulnerability in WordPress core can be exploited anonymously, impacting millions of sites. Additionally, zero-day vulnerabilities in SonicWall SMA devices have been exploited by a threat actor prior to public disclosure, emphasizing the urgent need for patching and security enhancements across affected systems.
Exploit brokers have offered $500,000 for a zero-day remote code execution (RCE) vulnerability in WordPress. A security researcher utilized the recently launched GPT5.6 Sol Ultra to successfully identify this vulnerability for a minimal investment of $25, which highlights the potential of AI in finding security flaws.
Two critical vulnerabilities in WordPress, tracked as CVE-2026-60137 and CVE-2026-63030, are actively being exploited. Following their discovery, WordPress issued patches and enabled forced updates due to the flaw's severity, which allows remote code execution on vulnerable sites.
Public exploits for critical RCE vulnerabilities in WordPress Core prompt immediate patching. Affected versions are 6.9.x and 7.0.x; over 500 million sites may be at risk.
Cloudflare has implemented new WAF protections against two critical vulnerabilities in WordPress, including an unauthenticated RCE and SQL injection. This deployment aims to mitigate risks for users while they apply necessary patches, as WordPress has also released updates addressing these issues.
A core vulnerability in WordPress allows unauthenticated attackers to run code on sites using versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. The issue was addressed in updates released on July 17, 2026, impacting potentially over 500 million websites.