Hackers Exploit WP2Shell WordPress Flaws for Unauthenticated Remote Code Execution
Image: Межа. Новини України.

Hackers Exploit WP2Shell WordPress Flaws for Unauthenticated Remote Code Execution

20 July, 2026.Technology and Science.11 sources

The story in 15 seconds

  • WP2Shell vulnerabilities in WordPress core allow unauthenticated remote code execution.
  • Attacks are ongoing in the wild, affecting tens of millions of sites.
  • Patches released: WordPress 6.9.5 and 7.0.2 mitigate WP2Shell.

The divide · 1 of 2

SecurityWeek confirms in-the-wild attacks; Security Boulevard says Rapid7 found none.

Who skipped what

Blind spots

If you only read Western Alternative outlets, you would not know:

  • Rapid7 said it was unaware of in-the-wild exploitation.
  • Cloudflare deployed emergency WAF protection for customers.

Skipped by DiarioBitcoin, Gadget Review

How each outlet frames it

Every outlet we compared, the headline it ran, and a link to the original article.

Source Diversity
11 sources
Other
5
Western Alternative
3
Local Western
1
Latin American
1
Western Mainstream
1

Local Western

01net
01net

Millions of sites are vulnerable: two critical flaws have been discovered in the core of WordPress.

20 July, 2026

Read the original →

Latin American

Cadena 3 Argentina
Cadena 3 Argentina

Hackers are exploiting critical WordPress vulnerabilities, putting millions of websites at risk.

20 July, 2026

Read the original →

Other

Cybernews
Cybernews

Massive WordPress vulnerability requires no preconditions: hackers can run malicious code

20 July, 2026

Read the original →
Korben
Korben

WP2Shell - La faille qui permet de pirater WordPress sans aucun plugin

19 July, 2026

Read the original →
Security Boulevard
Security Boulevard

WordPress Critical RCE Security Flaw a Threat to Millions of Websites

20 July, 2026

Read the original →
SecurityWeek
SecurityWeek

WP2Shell WordPress Vulnerabilities Exploited in the Wild

20 July, 2026

Read the original →
Межа. Новини України.
Межа. Новини України.

Hackers Target Millions of WordPress Sites, Experts Urge Immediate Updates

20 July, 2026

Read the original →

Western Alternative

DiarioBitcoin
DiarioBitcoin

Hackers exploit WordPress's critical flaws and threaten millions of websites.

20 July, 2026

Read the original →
Gadget Review
Gadget Review

Hackers Exploit Patched WordPress Bugs – Millions of Sites Still at Risk

20 July, 2026

Read the original →
The Tech Buzz
The Tech Buzz

WordPress Security Flaws Expose Millions of Sites to Takeover

20 July, 2026

Read the original →

Western Mainstream

TechCrunch
TechCrunch

Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk

20 July, 2026

Read the original →

Full story

WP2Shell targets WordPress

Hackers are exploiting two chained WordPress core vulnerabilities dubbed “WP2Shell” to gain unauthenticated remote code execution on default installations, with WordPress 7.0.2 patching the flaws.

WordPress is the victim of a security incident

01net01net

The vulnerable versions span WordPress 6.8 through 7.0.1 and the 7.1 beta, while WordPress enabled forced updates where possible after issuing emergency releases of 6.9.5 and 7.0.2.

Image from 01net
01net01net

Security researcher Adam Kues of Searchlight Cyber discovered the WP2Shell chain, which combines two REST API vulnerabilities to deliver unauthenticated remote code execution, and a separate SQL injection bug compounds the damage.

One estimate cited by TechCrunch puts the number of vulnerable WordPress websites at tens of millions as of Monday, and WordPress’ official stats say there are more than 400 million websites running the flawed versions.

TechCrunch also quotes Daniel Card estimating that fewer than 15% of a sample of around 3,500 WordPress websites are vulnerable, projecting a total of around 90 million if applied across the wider population.

Exploitation in the wild

Since the patches, cybersecurity firms including Patchstack, Hexastrike, and WatchTowr have warned that hackers are exploiting the vulnerabilities in the wild, taking over websites that are still running susceptible versions of WordPress.

SecurityWeek similarly describes the WP2Shell attack as having “no preconditions” and being exploitable by an anonymous user in a stock install of WordPress with no plugins.

Image from Cadena 3 Argentina
Cadena 3 ArgentinaCadena 3 Argentina

TechCrunch reports that WordPress urged people who run its software to update it “immediately,” and that the severity led WordPress to enable forced updates where possible.

In a separate account, SecurityWeek says “The attack has no preconditions and can be exploited by an anonymous user,” and it identifies the vulnerabilities as CVE-2026-60137 and CVE-2026-63030.

TechCrunch also notes that WordPress.org did not immediately respond to a request for comment, while Megan Fox said Automattic deployed code updates immediately across millions of sites after the releases.

What’s at stake next

The risk is amplified by WordPress’s scale, with Searchlight Cyber estimating that over 500 million websites use WordPress and with multiple outlets tying the flaw’s reach to the platform’s widespread deployment.

A default, unmodified WordPress (WP) website can be completely compromised with no login or plugin installation required

CybernewsCybernews

Cybernews says Cloudflare has deployed emergency Web Application Firewall (WAF) protections to reduce the risk of exploitation, and it adds that Cloudflare said “No login or user interaction is required to exploit this vulnerability.”

Security Boulevard frames the issue as pre-authentication remote code execution (RCE) attacks on WordPress Core, warning that the vulnerability reportedly allows an unauthenticated attacker to execute code via the WordPress REST API batch endpoint.

For mitigation, Security Boulevard says WordPress enabled forced updates through its auto-update system for sites running the impacted versions and instructs others to manually update by clicking “updates” and then “update now.”

TechCrunch reports that Megan Fox said Automattic protected sites even before the release and deployed the code updates immediately across millions of sites once the updates were published.

The deep audit

How victims, perpetrators and terms are handled across outlets.

More on Technology and Science