Hackers Exploit Critical WordPress Flaws Worldwide

Two flaws in WordPress core allow attackers to seize unpatched websites without logging in, with researchers detecting successful attacks and mass scanning.

Topics

  • Image Credit- Chetan Jha/ MIT Sloan Management Review India

    Hackers are exploiting two newly patched vulnerabilities in WordPress core that can be chained to take control of websites without login credentials, TechCrunch reported, citing cybersecurity researchers.

    Cybersecurity companies have detected successful attacks, malicious plug-in installations and widespread scanning for vulnerable websites.

    The flaws were first disclosed on July 17 by Searchlight Cyber, whose researcher Adam Kues discovered the attack chain and named it WP2Shell. 

    WordPress released fixes the same day and urged administrators to update immediately.

    Because of the severity, WordPress also forced automatic updates on affected installations. 

    The vulnerabilities, tracked as CVE-2026-60137 and CVE-2026-63030, affect WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1.

    CVE-2026-60137 is an SQL injection flaw while CVE-2026-63030 is a weakness in a WordPress system that allows websites and applications to exchange information and instructions.

    The combined attack chain, known as “WP2Shell,” was fixed in versions 6.9.5 and 7.0.2.

    Together, they allow attackers to bypass authentication, create malicious administrator accounts and remotely execute code on a standard WordPress installation without relying on a vulnerable plug-in.

    Attackers can use that access to steal credentials, install malicious plug-ins or deploy additional malware.

    Wiz, Google’s cloud security company, said attackers had exploited the flaws against cloud-hosted WordPress sites and installed persistent webshells disguised as plug-ins.

    Cybersecurity consultant Daniel Card told TechCrunch that fewer than 15% of WordPress sites in a sample of about 3,500 remained vulnerable. Applying that estimate more broadly could mean that about 90 million websites worldwide were still exposed.

    Some intruders used those accounts to install fake WordPress plug-ins and download additional tools, including remote-access malware.

    Topics

    More Like This

    You must to post a comment.

    First time here? : Comment on articles and get access to many more articles.