WP2Shell WordPress Vulnerabilities Exploited in the Wild
Two newly patched WordPress vulnerabilities are being exploited in the wild, with attacks beginning shortly after they came to light.
The vulnerabilities have been dubbed WP2Shell and they are officially tracked as CVE-2026-60137 and CVE-2026-63030.
According to Searchlight Cyber, whose researchers discovered the flaws, WordPress versions 6.9.9 through 6.9.4 and 7.0.0 through 7.0.1 are affected.
“The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins,” the security firm warned.
WordPress announced patches on Friday with the release of versions 6.9.5 and 7.0.2.
“Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions,” WordPress developers said.
Advertisement. Scroll to continue reading.
Cloudflare has also rolled out rules to detect exploitation and protect customers whose installations were not immediately patched.
CVE-2026-60137 is a high-severity SQL injection bug and CVE-2026-63030 is...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE