Skip to content
MagnaNet Network MagnaNet Network

  • Home
  • About Us
    • About Us
    • Advertising Policy
    • Cookie Policy
    • Affiliate Disclosure
    • Disclaimer
    • DMCA
    • Terms of Service
    • Privacy Policy
  • Contact Us
  • FAQ
  • Sitemap
MagnaNet Network
MagnaNet Network

Widespread Exploitation of Critical WordPress Vulnerabilities Enables Unauthenticated Remote Code Execution, Threatening Global Websites

Cahyo Dewo, July 21, 2026

Attackers have initiated widespread exploitation of two critical vulnerabilities within the WordPress content management system that, when chained together, allow for unauthenticated remote code execution (RCE) and the complete compromise of vulnerable websites. This severe threat, collectively codenamed wp2shell, has quickly escalated from initial targeted attacks to broad internet scanning, impacting organizations of all sizes and across diverse sectors globally. The vulnerabilities, tracked as CVE-2026-63030 and CVE-2026-60137, represent a significant risk to the estimated 43% of all websites powered by WordPress.

Discovery and Rapid Escalation of Exploitation

The security flaws were first publicly identified and assigned CVEs for the year 2026, indicating they were recently discovered and reported, yet exploitation began almost immediately upon their public disclosure. By the early hours of Saturday morning (UTC), successful exploitation campaigns were already well underway. Jake Knott, a principal security researcher at watchTowr, confirmed the rapid progression of attacks to The Hacker News, stating, "Initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public." He further emphasized the pervasive nature of the threat, noting, "From our vantage point across a global client base, we are seeing widespread impact of this vulnerability across organizations of every size and every vertical." This immediate and broad impact underscores the critical nature of these vulnerabilities and the agility of threat actors in leveraging newly disclosed weaknesses.

The rapid weaponization of these flaws was facilitated by the swift public release of exploit code, drastically lowering the barrier for entry for malicious actors. Security researchers and cybersecurity firms began observing a surge in attack attempts almost concurrently with the vulnerability details becoming known. The speed at which these vulnerabilities moved from disclosure to active exploitation highlights a recurring challenge in cybersecurity: the race between defenders patching systems and attackers weaponizing new flaws.

Telemetry Data Reveals Global Attack Footprint

Initial telemetry data captured by KEVIntel, a cybersecurity intelligence firm, provides a glimpse into the geographical distribution of the early exploitation attempts. Their sensor telemetry shows that at least 13 unique IP addresses, originating from a diverse set of countries including Switzerland, Germany, the U.K., Indonesia, Lithuania, the Netherlands, and Singapore, have been directly linked to the exploitation of CVE-2026-63030. This global footprint indicates that the threat actors are not confined to a single region but are operating internationally, leveraging distributed infrastructure to launch their attacks.

Ryan Dewhurst, founder and CEO of KEVIntel, elaborated on the evolving nature of the attacks. He reported that exploitation efforts rapidly expanded from narrowly targeting WordPress-specific sensors to broad internet scanning campaigns. These scans are designed to identify any vulnerable WordPress instances across the web, with the observed requests precisely matching publicly available proof-of-concept (PoC) exploits. This transition from specific targeting to opportunistic mass scanning signifies a heightened threat level, as attackers aim to cast a wide net to compromise as many unpatched systems as possible. The sophistication of these attacks also includes the use of multiple SQL injection techniques, such as blind, UNION-based, and Boolean-based payloads, indicating a varied and adaptive approach by the attackers.

The Technical Underpinnings of wp2shell

The wp2shell exploit chain hinges on two distinct yet interconnected security flaws. CVE-2026-63030, the primary RCE vulnerability, allows for unauthenticated remote code execution specifically when a persistent object cache is not in use. This condition is prevalent in many standard WordPress deployments, making a large segment of the platform vulnerable. The second vulnerability, CVE-2026-60137, is an SQL injection flaw that acts as the initial entry point for the attack. While CVE-2026-60137 is present in WordPress versions from 6.8 onwards, the full RCE capability through CVE-2026-63030 impacts versions from 6.9. It’s crucial for users to understand that these CVEs, despite their 2026 designation, are actively being exploited in the current timeframe, likely due to their assignment date in the vulnerability database.

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Ben Marr, a security engineer at Intruder, provided a detailed technical explanation of the exploit chain. He explained that the attack leverages a two-part vulnerability chain to achieve unauthenticated SQL injection on a default WordPress installation with just a single HTTP request. "CVE-2026-60137 is the entry point – a route confusion bug in the REST API batch endpoint that bypasses authentication, allowing an attacker to invoke internal handlers without any permission check," Marr stated. This critical bypass allows attackers to interact with internal WordPress functions that would normally require user authentication.

The second part of the chain involves CVE-2026-63030, which arises from the improper sanitization of the ‘author__not_in’ parameter within ‘WP_Query’. When untrusted data is passed to this parameter, often via a plugin or theme, it allows crafted input to alter a database query. This manipulation can lead to unauthorized access, data exfiltration, or, crucially, the execution of arbitrary code on the server. The fact that this attack has "no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins," as highlighted by Searchlight Cyber, makes it exceptionally dangerous. Technical details about the exploit have been largely withheld by security researchers to prevent further weaponization, emphasizing the severity of the issue.

The Unsettling Role of AI in Vulnerability Discovery

Adding a new dimension to the threat landscape, the exploit chain was reportedly discovered by Searchlight Cyber using OpenAI’s GPT 5.6 Sol, a large language model, in just over 10 hours. This revelation underscores the growing capabilities of advanced AI in cybersecurity, not only for defense but also for offense. Ryan Dewhurst of KEVIntel corroborated this, stating, "In our own testing, AI-assisted analysis made reproducing the vulnerability and developing a working proof of concept trivial. This significantly lowers the technical barrier for producing exploit code once sufficient vulnerability details are publicly available."

The use of AI like GPT 5.6 Sol to discover and replicate complex vulnerabilities presents a paradigm shift. Traditionally, finding such intricate exploit chains required highly specialized human expertise and significant time. AI’s ability to automate and accelerate this process means that vulnerabilities could be discovered and exploited much faster, potentially reducing the window for defenders to patch their systems. This development signals a future where AI-powered tools will play an increasingly prominent role in both offensive and defensive cybersecurity strategies, necessitating a re-evaluation of current security postures and response mechanisms.

Scale of Impact and Observed Post-Exploitation Activities

The sheer scale of WordPress deployments globally means that even a small percentage of vulnerable instances translates into a massive attack surface. Data from Google-owned Wiz paints a stark picture: at the time these CVEs were published, 60% of organizations using WordPress initially had at least one vulnerable instance. More alarmingly, 25% of these organizations were exposing a vulnerable server directly to the internet, making them prime targets for opportunistic attackers. While these figures have since seen a reduction as organizations apply patches, a significant number of installations likely remain at risk.

Wiz researchers Shahar Dorfman and Gili Tikochinski have detailed several post-exploitation activities observed following the abuse of these two flaws. These activities include:

  • Hashed Credential Exfiltration: Attackers are primarily focused on extracting hashed user credentials, particularly those of administrators, which can then be cracked offline to gain full access.
  • SQL Injection Techniques: The use of blind, UNION-based, and Boolean-based SQL injection payloads indicates a concerted effort to manipulate databases, potentially leading to data theft or further system compromise.
  • Deployment of Web Shells: A particularly concerning observation is the deployment of a 150 KB web shell disguised as a legitimate WordPress security plugin named CMSmap. This sophisticated web shell acts as a "full-featured attack platform," offering capabilities such as file management, database access, port scanning, batch code injection, and multiple privilege escalation modules, including MySQL User-Defined Function (UDF) exploitation. This grants attackers persistent and comprehensive control over the compromised server.
  • Creation of Backdoor Administrator Accounts: More than 100 backdoor administrator accounts are reported to have been created post-exploitation. These rogue accounts provide attackers with an alternative entry point, allowing them to deploy fake WordPress plugins for code execution or download secondary tools to further compromise the system.
  • Installation of Remote Access Trojans (RATs): In at least one documented case, a threat actor was observed repeatedly attempting to install Overlord RAT, a Golang-based remote access trojan. RATs provide attackers with extensive control over a compromised system, enabling surveillance, data exfiltration, and further malicious activities.

Wiz researchers also noted high-volume scanning activity without subsequent post-exploitation, suggesting that opportunistic mass-scanning campaigns are underway to identify vulnerable targets, running concurrently with legitimate security scanning activities. While they have yet to identify lateral movement or data exfiltration on a broader scale, monitoring and investigation remain ongoing.

Mitigation and Defensive Measures

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

The cybersecurity community has issued urgent calls for action. Defenders are strongly recommended to immediately inspect their WordPress instances for any indicators of compromise, regardless of whether they have already applied patches. This includes diligently checking for newly created administrator accounts, suspicious or malicious plugins, and any other unusual or unfamiliar files within their WordPress directories. Rooting out the threat entirely requires a thorough forensic investigation beyond mere patching.

Fortunately, several defensive measures have helped to reduce the potential "blast radius" of these vulnerabilities. Ryan Dewhurst pointed out that WordPress has supported automatic background updates for security releases for several years. Additionally, some infrastructure providers received advance notice of the vulnerabilities, enabling them to deploy virtual patches or Web Application Firewall (WAF) rules quickly. These proactive measures significantly reduced the exposure window for sites that either updated automatically or were protected by relevant WAF configurations.

However, Dewhurst cautioned that sites where automatic updates were disabled, unsupported, or unsuccessful might still remain vulnerable. Given the immense scale of WordPress deployment across the web, a substantial number of installations could still be unpatched. Therefore, operators of sites that were vulnerable when public exploit code became available are urged to update immediately and conduct a comprehensive review of their systems for any indicators of compromise. Applying the patch alone may not be sufficient if an initial compromise has already occurred.

Broader Implications for Web Security

The wp2shell vulnerabilities underscore several critical challenges facing the internet’s security landscape. The first is the sheer ubiquity of popular platforms like WordPress, which makes them highly attractive targets for attackers. A single critical flaw can expose millions of websites, ranging from personal blogs to large enterprise portals.

Secondly, the speed of exploitation following public disclosure continues to accelerate. The interval between a vulnerability being announced and actively exploited is shrinking, placing immense pressure on developers to release patches quickly and on administrators to apply them without delay.

Finally, the emergence of AI as a tool for vulnerability discovery and exploit development is a game-changer. While AI can undoubtedly enhance defensive capabilities, its potential misuse by malicious actors raises serious concerns about the future of cybersecurity. This necessitates not only more robust security practices but also ongoing research into AI-driven defense mechanisms.

The wp2shell incident serves as a stark reminder of the constant vigilance required in the digital realm. Organizations and individuals alike must prioritize patching, implement strong security monitoring, and prepare for rapid response to emergent threats to safeguard their online presence against increasingly sophisticated attacks.

Cybersecurity & Digital Privacy codecriticalCybercrimeenablesexecutionexploitationGlobalHackingPrivacyremoteSecuritythreateningunauthenticatedvulnerabilitieswebsiteswidespreadwordpress

Post navigation

Previous post
Next post

Recent Posts

Categories

  • AI & Machine Learning
  • Blockchain & Web3
  • Cloud Computing & Edge Tech
  • Cybersecurity & Digital Privacy
  • Data Center & Server Infrastructure
  • Digital Transformation & Strategy
  • Enterprise Software & DevOps
  • Global Telecom News
  • Internet of Things & Automation
  • Network Infrastructure & 5G
  • Semiconductors & Hardware
  • Space & Satellite Tech
©2026 MagnaNet Network | WordPress Theme by SuperbThemes