INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
| 2026-07-21 16:41 CRITICAL MEDIUM EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The recent incident data points indicate a sophisticated and widespread attack on vulnerable WordPress sites, exploiting the "wp2shell" critical vulnerability suite to deploy persistent webshells and install malicious plugins. The attackers have been probing SQL injection attacks to confirm vulnerabilities before delivering PHP webshells, with targeted sectors including finance and healthcare. Automatic security updates were quickly addressed by major software vendors, forcing installations of patched versions on supported sites. Researchers like SearchLight Cyber's Adam Kues have published follow-up reports detailing the exploit chain and developing a working exploit, highlighting the threat level and potential attack vectors. The incident highlights the importance of timely patching, monitoring logs for suspicious activity, inspecting installed plugins, and checking for rogue PHP file additions or newly created admin accounts to mitigate this type of attack.
Technical Mitigations AI-generated
* Regularly update WordPress and plugins: Ensure that all affected versions of WordPress (7.0.2, 6.9.5, and 6.8.6) and installed plugins are up-to-date to prevent exploitation.
* Monitor logs for suspicious activity: Regularly review server logs for any unusual or malicious requests related to the wp2shell vulnerabilities.
* Implement a web application firewall (WAF): Consider installing a WAF on your WordPress installation to help detect and block potential attacks.
* Use secure file inclusion protection: Configure your PHP configuration to prevent local file inclusion attempts, which can be used by attackers to retrieve sensitive data or execute malicious code.
* Limit administrator privileges: Restrict administrator access to only necessary features and functions to reduce the attack surface.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
wp•••••.com
ad•••••.php
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-63030CVE-2026-63030
CVE-2026-60137CVE-2026-60137
Target & Sectors
Global Scope
Incident Timeline
December 2025
The remote code execution exploit, discovered by Searchlight Cyber using OpenAI GPT 5.6 Sol, allows unauthenticated attackers to gain remote code execution on default WordPress installations in any version released since December 2025.
Click on any entity below to view its context and source!
tactic
Remote Code Execution
The exploit chain,
discovered
by Searchlight Cyber using
OpenAI GPT 5.6 Sol
in over 10 hours, essentially allows unauthenticated attackers to gain remote code execution on default WordPress installations in any WordPress version released since December 2025.
infrastructure
5.6
The exploit chain,
discovered
by Searchlight Cyber using
OpenAI GPT 5.6 Sol
in over 10 hours, essentially allows unauthenticated attackers to gain remote code execution on default WordPress installations in any WordPress version released since December 2025.
organisation
GPT
The exploit chain,
discovered
by Searchlight Cyber using
OpenAI GPT 5.6 Sol
in over 10 hours, essentially allows unauthenticated attackers to gain remote code execution on default WordPress installations in any WordPress version released since December 2025.
general_metric
5.6 OpenAI Sol
The exploit chain,
discovered
by Searchlight Cyber using
OpenAI GPT 5.6 Sol
in over 10 hours, essentially allows unauthenticated attackers to gain remote code execution on default WordPress installations in any WordPress version released since December 2025.
general_metric
10 hours
The exploit chain,
discovered
by Searchlight Cyber using
OpenAI GPT 5.6 Sol
in over 10 hours, essentially allows unauthenticated attackers to gain remote code execution on default WordPress installations in any WordPress version released since December 2025.
July 17
Threat actors used a vulnerability in WordPress to exploit the site on July 17 within 13 minutes of the security update being issued.
Click on any entity below to view its context and source!
organisation
UTC
WordPress security firm Defiant has also published an
“aftermath” post
stating that the first exploitation-related probing was observed at 23:29 UTC on July 17, followed by a clear SQL injection attempt just 13 minutes later.
general_metric
13 minutes
WordPress security firm Defiant has also published an
“aftermath” post
stating that the first exploitation-related probing was observed at 23:29 UTC on July 17, followed by a clear SQL injection attempt just 13 minutes later.
Sunday, July 19
VulnCheck discovered and verified more than two-dozen unique PoC exploits targeting WordPress sites via the wp2shell vulnerability as of Sunday, July 19.
Click on any entity below to view its context and source!
organisation
VulnCheck
In a blog post,
VulnCheck
said it had verified more than two-dozen unique PoC exploits targeting WP2Shell as of Sunday, July 19, or barely two days after initial bug disclosure.
organisation
PoC
In a blog post,
VulnCheck
said it had verified more than two-dozen unique PoC exploits targeting WP2Shell as of Sunday, July 19, or barely two days after initial bug disclosure.
2026/07/20
Threat actors used AI tools to discover and exploit a vulnerability in the WordPress software, allowing them to gain remote access to targeted sites.
2026/07/21
Attackers began exploiting two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, which allow remote code execution (RCE) on vulnerable sites without authentication.
Click on any entity below to view its context and source!
organisation
Dean of Research at Sans Technology Insitute
Malicious plugin installed on vulnerable sites
Source: Wiz
A separate report on active wp2shell exploitation from
Johannes B. Ullrich
, Dean of Research at Sans Technology Insitute, describes two-stage attacks that start with probing SQL injection to confirm the vulnerability before delivering a PHP webshell to the server.
organisation
SQL
Malicious plugin installed on vulnerable sites
Source: Wiz
A separate report on active wp2shell exploitation from
Johannes B. Ullrich
, Dean of Research at Sans Technology Insitute, describes two-stage attacks that start with probing SQL injection to confirm the vulnerability before delivering a PHP webshell to the server.
While the SQL injection vulnerability (CVE-2026-60137) is present from version 6.8 onwards, the RCE affects versions from 6.9.
Related:
ClickFix's Mushrooming Ecosystem Demands New Defense Tactics
WP2Shell: A Dangerous Cyberattack Duo
CVE-2026-60137 is an
SQL injection vulnerability
in WordPress Core that allows an attacker to manipulate database queries and access data that should not be exposed.
CVE-2026-60137
is a high-severity SQL injection flaw in the
author__not_in
parameter of
WP_Query
, affecting.
According to the GitHub advisory, the flaw can be combined with the SQL injection issue to achieve remote code execution.
organisation
PHP
Malicious plugin installed on vulnerable sites
Source: Wiz
A separate report on active wp2shell exploitation from
Johannes B. Ullrich
, Dean of Research at Sans Technology Insitute, describes two-stage attacks that start with probing SQL injection to confirm the vulnerability before delivering a PHP webshell to the server.
The cloud security subsidiary has observed the following post-exploitation activities following the abuse of the two flaws -
Uploading a malicious plugin
Enumerating users and harvesting admin usernames and email addresses
Performing local file inclusion (LFI) attacks to target database credentials and authentication keys for exfiltration
Accessing the admin panel and successfully authenticating themselves
Uploading a bare-bones PHP web shell that facilitates remote code execution
"We've also observed high-volume scanning activity without subsequent post-exploitation, suggesting opportunistic mass-scanning campaigns seeking to identify vulnerable targets alongside legitimate security scanning activity," Wiz researchers Shahar Dorfman and Gili Tikochinski
said
.
infrastructure
6.8
While the SQL injection vulnerability (CVE-2026-60137) is present from version 6.8 onwards, the RCE affects versions from 6.9.
infrastructure
6.9
While the SQL injection vulnerability (CVE-2026-60137) is present from version 6.8 onwards, the RCE affects versions from 6.9.
The flaws, tracked as CVE-2026-63030 and CVE-2026-60137, can be chained to achieve pre-authentication remote code execution on default WordPress installations running versions 6.9.x and 7.0.x.
The wp2shell attack consists of two flaws, tracked as CVE-2026-63030 and CVE-2026-60137, that can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x.
organisation
RCE
While the SQL injection vulnerability (CVE-2026-60137) is present from version 6.8 onwards, the RCE affects versions from 6.9.
According to the WordPress advisories, the complete RCE chain affects WordPress 6.9.0 through 6.9.4 and WordPress 7.0.0 through 7.0.1.
organisation
WordPress Core
Related:
ClickFix's Mushrooming Ecosystem Demands New Defense Tactics
WP2Shell: A Dangerous Cyberattack Duo
CVE-2026-60137 is an
SQL injection vulnerability
in WordPress Core that allows an attacker to manipulate database queries and access data that should not be exposed.
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers.
Public proof-of-concept exploits are now available for the critical wp2shell vulnerabilities affecting WordPress Core.
Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately.
organisation
ClickFix
Related:
ClickFix's Mushrooming Ecosystem Demands New Defense Tactics
WP2Shell: A Dangerous Cyberattack Duo
CVE-2026-60137 is an
SQL injection vulnerability
in WordPress Core that allows an attacker to manipulate database queries and access data that should not be exposed.
organisation
CVE-2026-60137
CVE-2026-60137
is a high-severity SQL injection flaw in the
author__not_in
parameter of
WP_Query
, affecting.
organisation
GitHub
According to the GitHub advisory, the flaw can be combined with the SQL injection issue to achieve remote code execution.
organisation
CMSmap
"We have yet to identify lateral movement or data exfiltration, but we continue to monitor and investigate."
Also observed as part of the activity is a 150 KB web shell that's disguised as a legitimate WordPress security plugin called CMSmap.
Installation of PHP webshells ranging from simple one-liner backdoors to feature-rich, obfuscated shells disguised as plugins (CMSmap).
organisation
KB
"We have yet to identify lateral movement or data exfiltration, but we continue to monitor and investigate."
Also observed as part of the activity is a 150 KB web shell that's disguised as a legitimate WordPress security plugin called CMSmap.
organisation
KEVIntel
"
Telemetry data captured by KEVIntel
shows
that 13 unique IP addresses from Switzerland, Germany, the U.K., Indonesia, Lithuania, the Netherlands, and Singapore have been linked to the exploitation of CVE-2026-63030.
organisation
IP
"
Telemetry data captured by KEVIntel
shows
that 13 unique IP addresses from Switzerland, Germany, the U.K., Indonesia, Lithuania, the Netherlands, and Singapore have been linked to the exploitation of CVE-2026-63030.
infrastructure
13 unique IP addresses
"
Telemetry data captured by KEVIntel
shows
that 13 unique IP addresses from Switzerland, Germany, the U.K., Indonesia, Lithuania, the Netherlands, and Singapore have been linked to the exploitation of CVE-2026-63030.
organisation
CVE-2026
The two security flaws, tracked as
CVE-2026-63030 and CVE-2026-60137
, have been codenamed
wp2shell
.
"Once the vulnerabilities were publicly disclosed, reproducing them with the help of frontier AI models was only a matter of time and tokens," he says, pointing to how watchTowr was able to trivially reproduce CVE-2026-63030 within minutes of disclosure, and CVE-2026-60137 with some additional effort.
organisation
Cloudflare
According to Cloudflare, CVE-2026-63030
enables
unauthenticated remote code execution (RCE) only when persistent object cache is not in use.
Cloudflare also announced that it has deployed Web Application Firewall (WAF) protections for both vulnerabilities across all plans, including free accounts, that are proxied behind its platform.
organisation
API
However, it becomes reachable without authentication when chained with CVE-2026-63030, a logic flaw in WordPress's Batch REST API, which lets applications bundle multiple requests, such as creating, updating, or retrieving content, into one API call.
"CVE-2026-60137 is the entry point - a route confusion bug in the REST API batch endpoint that bypasses authentication, allowing an attacker to invoke internal handlers without any permission check.
The
critical exploit chain
abuses the WordPress REST API’s batch-processing feature, allowing remote attackers to execute code on vulnerable installations without the need to authenticate.
If patching is not possible, administrators can temporarily reduce risk by blocking anonymous access to the REST API batch endpoint through a security plugin or WAF rules targeting
/wp-json/batch/v1
and
?rest_route=/batch/v1
.
infrastructure
7.0
The flaws, tracked as CVE-2026-63030 and CVE-2026-60137, can be chained to achieve pre-authentication remote code execution on default WordPress installations running versions 6.9.x and 7.0.x.
The wp2shell attack consists of two flaws, tracked as CVE-2026-63030 and CVE-2026-60137, that can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x.
infrastructure
7.0.2
Active exploitation was quickly confirmed, immediately after WordPress addressed the problem in versions 7.0.2, 6.9.5, and 6.8.6, forcing automatic security updates for supported installations.
“The 7.0.2 security release addresses one critical and one high severity security issue.”
Site owners should update immediately to WordPress 7.0.2 or 6.9.5, which prevent the exploitation of the wp2shell attack chain.
Due to the severity of the vulnerabilities, the WordPress security team has enabled forced automatic security updates for supported installations running affected versions, urging site owners to update to WordPress 7.0.2 or 6.9.5 immediately.
The full wp2shell attack chain has been fixed in WordPress 6.9.5 and 7.0.2.
The watchTowr team is already seeing PoC exploits in circulation, and we are beginning to see the first signs of in-the-wild exploitation."
Given the availability of public proof-of-concept exploits and the first reported signs of in-the-wild exploitation, administrators should ensure their sites are updated to WordPress 7.0.2 or 6.9.5 as soon as possible.
infrastructure
6.9.5
Active exploitation was quickly confirmed, immediately after WordPress addressed the problem in versions 7.0.2, 6.9.5, and 6.8.6, forcing automatic security updates for supported installations.
Site owners should update immediately to WordPress 7.0.2 or 6.9.5, which prevent the exploitation of the wp2shell attack chain.
Due to the severity of the vulnerabilities, the WordPress security team has enabled forced automatic security updates for supported installations running affected versions, urging site owners to update to WordPress 7.0.2 or 6.9.5 immediately.
The full wp2shell attack chain has been fixed in WordPress 6.9.5 and 7.0.2.
The watchTowr team is already seeing PoC exploits in circulation, and we are beginning to see the first signs of in-the-wild exploitation."
Given the availability of public proof-of-concept exploits and the first reported signs of in-the-wild exploitation, administrators should ensure their sites are updated to WordPress 7.0.2 or 6.9.5 as soon as possible.
infrastructure
6.8.6
Active exploitation was quickly confirmed, immediately after WordPress addressed the problem in versions 7.0.2, 6.9.5, and 6.8.6, forcing automatic security updates for supported installations.
organisation
WordPress
WordPress flaws exploited to install webshells.
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning.
Attackers have begun widely exploiting two critical vulnerabilities in WordPress that, when chained, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.
Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits
Public exploits are now available for two critical WordPress flaws that attackers can chain to gain remote code execution without authentication.
WordPress Core "wp2shell" RCE flaws get public exploits, patch now.
organisation
Abuse of WordPress
Abuse of WordPress plugin upload functionality to install malicious add-ons.
organisation
Installation of PHP
Installation of PHP webshells ranging from simple one-liner backdoors to feature-rich, obfuscated shells disguised as plugins (CMSmap).
organisation
Querying the WordPress
Querying the WordPress REST API to collect administrator usernames and email addresses.
organisation
backtick
The webshell code that Ullrich published checked the availability of several PHP functions -
system()
,
passthru()
,
exec()
,
shell_exec()
,
popen()
, or the backtick operator, in an attempt to execute commands.
organisation
UTC
"By the early hours of Saturday morning (UTC), successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public," Jake Knott, principal security researcher at watchTowr, told The Hacker News in a statement.
By the early hours of Saturday morning (UTC), attackers were well underway exploiting the two flaws, initially using public exploit code to exfiltrate hashed credentials, and then executing code remotely on vulnerable systems as additional details became available.
organisation
The Hacker News
"By the early hours of Saturday morning (UTC), successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public," Jake Knott, principal security researcher at watchTowr, told The Hacker News in a statement.
organisation
Administrators of WordPress
Administrators of WordPress sites should immediately update to the patched versions, review logs for wp2shell-related requests, inspect installed plugins, and check for rogue PHP file additions or newly created admin accounts.
organisation
EDR
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
organisation
UDF
It acts as a "full-featured attack platform" supporting file management, database access, port scanning, batch code injection, and multiple privilege escalation modules, including MySQL UDF exploitation.
organisation
GPT
He says GPT 5.6 Sol Ultra helped find the vulnerabilities and develop the exploit chain in a matter of just 10 hours.
organisation
Intruder
"This exploit utilizes a two-part vulnerability chain to achieve unauthenticated SQL injection on a stock WordPress installation with a single HTTP request," Ben Marr, security engineer at Intruder, explained.
organisation
Google
"
Data from Google-owned Wiz suggests that 60% of organizations using WordPress initially had at least one vulnerable instance at the time these CVEs were published, and 25% were exposing a vulnerable server to the Internet.
organisation
WatchTowr
WatchTowr also said attackers have begun to spray the Internet in an indiscriminate fashion following the release of a public exploit, with its honeypots registering "tens of thousands of exploitation attempts.
WatchTowr's Knott says the company has been keeping a close eye on WP2Shell exploit activity since Friday via its Attacker Eye honeypot network.
organisation
Attacker Eye
WatchTowr's Knott says the company has been keeping a close eye on WP2Shell exploit activity since Friday via its Attacker Eye honeypot network.
organisation
Golang
In at least one case, a threat actor has been observed repeatedly attempting to install Overlord RAT, a Golang-based remote access trojan.
In one case, we watched a threat actor repeatedly attempt to pull down Overlord RAT, a Golang-based remote access Trojan," Knott says.
infrastructure
6.9.0
The vulnerabilities affect WordPress versions 6.9.0 - 6.9.4 and 7.0.0 - 7.0.1.
The full RCE exploit chain affects WordPress versions 6.9.0–6.9.4 and 7.0.0–7.0.1, according to WordPress security advisories.
infrastructure
6.9.4
The vulnerabilities affect WordPress versions 6.9.0 - 6.9.4 and 7.0.0 - 7.0.1.
The full RCE exploit chain affects WordPress versions 6.9.0–6.9.4 and 7.0.0–7.0.1, according to WordPress security advisories.
infrastructure
7.0.0
The vulnerabilities affect WordPress versions 6.9.0 - 6.9.4 and 7.0.0 - 7.0.1.
The full RCE exploit chain affects WordPress versions 6.9.0–6.9.4 and 7.0.0–7.0.1, according to WordPress security advisories.
infrastructure
7.0.1
The vulnerabilities affect WordPress versions 6.9.0 - 6.9.4 and 7.0.0 - 7.0.1.
The full RCE exploit chain affects WordPress versions 6.9.0–6.9.4 and 7.0.0–7.0.1, according to WordPress security advisories.
organisation
WordPress.org
"Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions," WordPress said.
Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions.”
"Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions.
organisation
Munch
RCE gets you the whole server," he says, "Put them and a bug that 'only' leaks data, and you end up with a web shell on the host."
What makes the two new vulnerabilities so attractive, Munch says, is that it they allow attackers to skip every step defenders usually get to interrupt: "No stolen password, no phished user, no vulnerable plug-in.
organisation
Cybersecurity
Cybersecurity researchers at Searchlight Cyber discovered the flaws that can allow remote attackers to compromise vulnerable sites without valid credentials, making immediate patching essential.
organisation
BleepingComputer
BleepingComputer has contacted Searchlight Cyber to confirm that its attack chain does not require an administrator password.
Tactical Metrics
Metrics
infrastructure
7.0.2
Software Version
Click for context!
Active exploitation was quickly confirmed, immediately after WordPress addressed the problem in versions 7.0.2, 6.9.5, and 6.8.6, forcing automatic security updates for supported installations.
“The 7.0.2 security release addresses one critical and one high severity security issue.”
Site owners should update immediately to WordPress 7.0.2 or 6.9.5, which prevent the exploitation of the wp2shell attack chain.
Due to the severity of the vulnerabilities, the WordPress security team has enabled forced automatic security updates for supported installations running affected versions, urging site owners to update to WordPress 7.0.2 or 6.9.5 immediately.
The full wp2shell attack chain has been fixed in WordPress 6.9.5 and 7.0.2.
…in-the-wild exploitation."
Given the availability of public proof-of-concept exploits and the first reported signs of in-the-wild exploitation, administrators should ensure their sites are updated to WordPress 7.0.2 or 6.9.5 as soon as possible.
Metrics
infrastructure
6.9.5
Software Version
Active exploitation was quickly confirmed, immediately after WordPress addressed the problem in versions 7.0.2, 6.9.5, and 6.8.6, forcing automatic security updates for supported installations.
Site owners should update immediately to WordPress 7.0.2 or 6.9.5, which prevent the exploitation of the wp2shell attack chain.
Due to the severity of the vulnerabilities, the WordPress security team has enabled forced automatic security updates for supported installations running affected versions, urging site owners to update to WordPress 7.0.2 or 6.9.5 immediately.
The full wp2shell attack chain has been fixed in WordPress 6.9.5 and 7.0.2.
…in-the-wild exploitation."
Given the availability of public proof-of-concept exploits and the first reported signs of in-the-wild exploitation, administrators should ensure their sites are updated to WordPress 7.0.2 or 6.9.5 as soon as possible.
Metrics
infrastructure
6.8.6
Software Version
Active exploitation was quickly confirmed, immediately after WordPress addressed the problem in versions 7.0.2, 6.9.5, and 6.8.6, forcing automatic security updates for supported installations.
Metrics
infrastructure
13
Unique Ip Addresses
"
Telemetry data captured by KEVIntel
shows
that 13 unique IP addresses from Switzerland, Germany, the U.K., Indonesia, Lithuania, the Netherlands, and Singapore have been linked to the exploitation of CVE-2026-63030.
Metrics
infrastructure
5.6
Software Version
The exploit chain,
discovered
by Searchlight Cyber using
OpenAI GPT 5.6 Sol
in over 10 hours, essentially allows unauthenticated attackers to gain remote code execution on default WordPress installations in any WordPress version released since…
Metrics
infrastructure
6.8
Software Version
While the SQL injection vulnerability (CVE-2026-60137) is present from version 6.8 onwards, the RCE affects versions from 6.9.
Metrics
infrastructure
6.9
Software Version
While the SQL injection vulnerability (CVE-2026-60137) is present from version 6.8 onwards, the RCE affects versions from 6.9.
The flaws, tracked as CVE-2026-63030 and CVE-2026-60137, can be chained to achieve pre-authentication remote code execution on default WordPress installations running versions 6.9.x and 7.0.x.
The wp2shell attack consists of two flaws, tracked as CVE-2026-63030 and CVE-2026-60137, that can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x.
Metrics
infrastructure
6.9.0
Software Version
The vulnerabilities affect WordPress versions 6.9.0 - 6.9.4 and 7.0.0 - 7.0.1.
The full RCE exploit chain affects WordPress versions 6.9.0–6.9.4 and 7.0.0–7.0.1, according to WordPress security advisories.
Metrics
infrastructure
6.9.4
Software Version
The vulnerabilities affect WordPress versions 6.9.0 - 6.9.4 and 7.0.0 - 7.0.1.
The full RCE exploit chain affects WordPress versions 6.9.0–6.9.4 and 7.0.0–7.0.1, according to WordPress security advisories.
Metrics
infrastructure
7.0.0
Software Version
The vulnerabilities affect WordPress versions 6.9.0 - 6.9.4 and 7.0.0 - 7.0.1.
The full RCE exploit chain affects WordPress versions 6.9.0–6.9.4 and 7.0.0–7.0.1, according to WordPress security advisories.
Metrics
infrastructure
7.0.1
Software Version
The vulnerabilities affect WordPress versions 6.9.0 - 6.9.4 and 7.0.0 - 7.0.1.
The full RCE exploit chain affects WordPress versions 6.9.0–6.9.4 and 7.0.0–7.0.1, according to WordPress security advisories.
Metrics
infrastructure
7.0
Software Version
The flaws, tracked as CVE-2026-63030 and CVE-2026-60137, can be chained to achieve pre-authentication remote code execution on default WordPress installations running versions 6.9.x and 7.0.x.
The wp2shell attack consists of two flaws, tracked as CVE-2026-63030 and CVE-2026-60137, that can be chained together to achieve pre-authentication remote code execution against WordPress installs running versions 6.9.x and 7.0.x.
Intelligence Sources
Dark Reading
2026-07-20
BleepingComputer
2026-07-21
Critical wp2shell WordPress flaws exploited to install webshells
BleepingComputer
Security Affairs
2026-07-19
BleepingComputer
2026-07-18
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
BleepingComputer
The Hacker News
2026-07-21
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-07-22T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
37x
organisation
Identified Entity
Dean of Research at Sans Technology Insitute
entity
11x
infrastructure
Software Version
7.0.2
version
6x
source region
Origin Country
Switzerland
country
5x
general metric
%
82
%
4x
tactic
Cyber Operation Type
Lateral Movement
tactic
4x
timeline
Temporal Reference
2026/07/20
date
2x
industry
Targeted Sector
Technology
sector
2x
vulnerability
Exploited CVE
CVE-2026-63030
cve
2x
general metric
Websites
124,580
websites
Contextual Telemetry
Context Block
9 METRICS
general metric
Minutes
13
minutes
infrastructure
Unique Ip Addresses
13
unique ip addresses
general metric
Kb Web Shell
150
kb web shell
general metric
Openai Sol
6
openai sol
general metric
Hours
10
hours
general metric
Version
7
version
general metric
Backdoor Administrator
100
backdoor administrator
tactic
MITRE ATT&CK Technique
T1588.005 - Exploits
technique
general metric
Wordpress
7
wordpress
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.