Hackers Exploit Critical WordPress Flaws Worldwide
Two flaws in WordPress core allow attackers to seize unpatched websites without logging in, with researchers detecting successful attacks and mass scanning.
Topics
News
- CuspAI Launches Global AI Network to Discover New Materials
- Google Develops Gemini-Linked Chip
- Kanishka Narayan Takes UK AI Policy Into Cabinet
- Hackers Exploit Critical WordPress Flaws Worldwide
- SEBI Fines CDSL Over Login Server Left Outside Its Own Security Controls
- Companies Double Down on AI Despite Elusive ROI: KPMG
Image Credit- Chetan Jha/ MIT Sloan Management Review India
Hackers are exploiting two newly patched vulnerabilities in WordPress core that can be chained to take control of websites without login credentials, TechCrunch reported, citing cybersecurity researchers.
Cybersecurity companies have detected successful attacks, malicious plug-in installations and widespread scanning for vulnerable websites.
The flaws were first disclosed on July 17 by Searchlight Cyber, whose researcher Adam Kues discovered the attack chain and named it WP2Shell.
WordPress released fixes the same day and urged administrators to update immediately.
Because of the severity, WordPress also forced automatic updates on affected installations.
The vulnerabilities, tracked as CVE-2026-60137 and CVE-2026-63030, affect WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.
CVE-2026-60137 is an SQL injection flaw while CVE-2026-63030 is a weakness in a WordPress system that allows websites and applications to exchange information and instructions.
The combined attack chain, known as “WP2Shell,” was fixed in versions 6.9.5 and 7.0.2.
Together, they allow attackers to bypass authentication, create malicious administrator accounts and remotely execute code on a standard WordPress installation without relying on a vulnerable plug-in.
Attackers can use that access to steal credentials, install malicious plug-ins or deploy additional malware.
Wiz, Google’s cloud security company, said attackers had exploited the flaws against cloud-hosted WordPress sites and installed persistent webshells disguised as plug-ins.
Cybersecurity consultant Daniel Card told TechCrunch that fewer than 15% of WordPress sites in a sample of about 3,500 remained vulnerable. Applying that estimate more broadly could mean that about 90 million websites worldwide were still exposed.
Some intruders used those accounts to install fake WordPress plug-ins and download additional tools, including remote-access malware.

