Full story
WP2Shell targets WordPress
Hackers are exploiting two chained WordPress core vulnerabilities dubbed “WP2Shell” to gain unauthenticated remote code execution on default installations, with WordPress 7.0.2 patching the flaws.
“WordPress is the victim of a security incident”
The vulnerable versions span WordPress 6.8 through 7.0.1 and the 7.1 beta, while WordPress enabled forced updates where possible after issuing emergency releases of 6.9.5 and 7.0.2.

Security researcher Adam Kues of Searchlight Cyber discovered the WP2Shell chain, which combines two REST API vulnerabilities to deliver unauthenticated remote code execution, and a separate SQL injection bug compounds the damage.
One estimate cited by TechCrunch puts the number of vulnerable WordPress websites at tens of millions as of Monday, and WordPress’ official stats say there are more than 400 million websites running the flawed versions.
TechCrunch also quotes Daniel Card estimating that fewer than 15% of a sample of around 3,500 WordPress websites are vulnerable, projecting a total of around 90 million if applied across the wider population.
Exploitation in the wild
Since the patches, cybersecurity firms including Patchstack, Hexastrike, and WatchTowr have warned that hackers are exploiting the vulnerabilities in the wild, taking over websites that are still running susceptible versions of WordPress.
SecurityWeek similarly describes the WP2Shell attack as having “no preconditions” and being exploitable by an anonymous user in a stock install of WordPress with no plugins.

TechCrunch reports that WordPress urged people who run its software to update it “immediately,” and that the severity led WordPress to enable forced updates where possible.
In a separate account, SecurityWeek says “The attack has no preconditions and can be exploited by an anonymous user,” and it identifies the vulnerabilities as CVE-2026-60137 and CVE-2026-63030.
TechCrunch also notes that WordPress.org did not immediately respond to a request for comment, while Megan Fox said Automattic deployed code updates immediately across millions of sites after the releases.
What’s at stake next
The risk is amplified by WordPress’s scale, with Searchlight Cyber estimating that over 500 million websites use WordPress and with multiple outlets tying the flaw’s reach to the platform’s widespread deployment.
“A default, unmodified WordPress (WP) website can be completely compromised with no login or plugin installation required”
Cybernews says Cloudflare has deployed emergency Web Application Firewall (WAF) protections to reduce the risk of exploitation, and it adds that Cloudflare said “No login or user interaction is required to exploit this vulnerability.”
Security Boulevard frames the issue as pre-authentication remote code execution (RCE) attacks on WordPress Core, warning that the vulnerability reportedly allows an unauthenticated attacker to execute code via the WordPress REST API batch endpoint.
For mitigation, Security Boulevard says WordPress enabled forced updates through its auto-update system for sites running the impacted versions and instructs others to manually update by clicking “updates” and then “update now.”
TechCrunch reports that Megan Fox said Automattic protected sites even before the release and deployed the code updates immediately across millions of sites once the updates were published.




