AUTO-UPDATED

Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits

WordPress has released critical security updates for versions 6.9.x and 7.0.x to patch a dangerous remote code execution vulnerability chain that allows attackers to compromise sites without authentication.

Key Points

  • WordPress versions 6.9.0–6.9.4 and 7.0.0–7.0.1 are vulnerable to a pre-authentication remote code execution exploit known as wp2shell.
  • The flaw chains a REST API batch-route confusion bug (CVE-2026-63030) with a high-severity SQL injection (CVE-2026-60137).
  • WordPress has issued mandatory forced automatic updates to version 7.0.2 and 6.9.5 to mitigate the risk for affected installations.
  • Researchers at Searchlight Cyber discovered the vulnerabilities, which can be exploited by anonymous users on default WordPress configurations without requiring plugins.
  • Administrators can use a provided online tool to check if their specific WordPress instance is currently vulnerable to these exploits.

Why it Matters

These vulnerabilities pose a significant threat because they affect over 500 million websites and require no user credentials to execute malicious code. Immediate patching is essential to prevent unauthorized site takeovers, as the widespread nature of the platform makes it a primary target for automated exploitation.
Securityaffairs.com Published by Pierluigi Paganini
Read original