Hackers Exploit WP2Shell WordPress Flaws for Unauthenticated Remote Code Execution
Image: Межа. Новини України.

Hackers Exploit WP2Shell WordPress Flaws for Unauthenticated Remote Code Execution

20 July, 2026.Technology and Science.11 sources

WP2Shell vulnerabilities in WordPress core allow unauthenticated remote code execution. Attacks are ongoing in the wild, affecting tens of millions of sites.

11 outlets2 divides3 facts unevenly coveredseverity 8/10

Beat 1 · The verdict

SecurityWeek confirms in-the-wild attacks; Security Boulevard says Rapid7 found none.

Beat 3 · What got skipped

2 Western Alternative outlets never mentioned: Rapid7 said it was unaware of in-the-wild exploitation.

DiarioBitcoin · Gadget Review

Read them yourself

Do not take our word for it. Here is what they published.

All 11 outlets

Full story

WP2Shell targets WordPress

Hackers are exploiting two chained WordPress core vulnerabilities dubbed “WP2Shell” to gain unauthenticated remote code execution on default installations, with WordPress 7.0.2 patching the flaws.

WordPress 7.0.2 patches the flaws.

Gadget ReviewGadget Review

The vulnerable versions span WordPress 6.8 through 7.0.1 and the 7.1 beta, while WordPress enabled forced updates where possible after issuing emergency releases of 6.9.5 and 7.0.2.

Image from 01net
01net01net

Security researcher Adam Kues of Searchlight Cyber discovered the WP2Shell chain, which combines two REST API vulnerabilities to deliver unauthenticated remote code execution, and a separate SQL injection bug compounds the damage.

One estimate cited by TechCrunch puts the number of vulnerable WordPress websites at tens of millions as of Monday, and WordPress’ official stats say there are more than 400 million websites running the flawed versions.

TechCrunch also quotes Daniel Card estimating that fewer than 15% of a sample of around 3,500 WordPress websites are vulnerable, projecting a total of around 90 million if applied across the wider population.

Exploitation in the wild

Since the patches, cybersecurity firms including Patchstack, Hexastrike, and WatchTowr have warned that hackers are exploiting the vulnerabilities in the wild, taking over websites that are still running susceptible versions of WordPress.

SecurityWeek similarly describes the WP2Shell attack as having “no preconditions” and being exploitable by an anonymous user in a stock install of WordPress with no plugins.

Image from Cadena 3 Argentina
Cadena 3 ArgentinaCadena 3 Argentina

TechCrunch reports that WordPress urged people who run its software to update it “immediately,” and that the severity led WordPress to enable forced updates where possible.

In a separate account, SecurityWeek says “The attack has no preconditions and can be exploited by an anonymous user,” and it identifies the vulnerabilities as CVE-2026-60137 and CVE-2026-63030.

TechCrunch also notes that WordPress.org did not immediately respond to a request for comment, while Megan Fox said Automattic deployed code updates immediately across millions of sites after the releases.

What’s at stake next

The risk is amplified by WordPress’s scale, with Searchlight Cyber estimating that over 500 million websites use WordPress and with multiple outlets tying the flaw’s reach to the platform’s widespread deployment.

“No login or user interaction is required to exploit this vulnerability,”

CybernewsCybernews

Cybernews says Cloudflare has deployed emergency Web Application Firewall (WAF) protections to reduce the risk of exploitation, and it adds that Cloudflare said “No login or user interaction is required to exploit this vulnerability.”

Security Boulevard frames the issue as pre-authentication remote code execution (RCE) attacks on WordPress Core, warning that the vulnerability reportedly allows an unauthenticated attacker to execute code via the WordPress REST API batch endpoint.

For mitigation, Security Boulevard says WordPress enabled forced updates through its auto-update system for sites running the impacted versions and instructs others to manually update by clicking “updates” and then “update now.”

TechCrunch reports that Megan Fox said Automattic protected sites even before the release and deployed the code updates immediately across millions of sites once the updates were published.