Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources CYBERATTACKS & DATA BREACHES VULNERABILITIES & THREATS THREAT INTELLIGENCE NEWS 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet. Jai Vijayan,Contributing Writer July 20, 2026 4 Min Read SOURCE: SILVER WINGS VIA SHUTTERSTOCK Attackers have begun widely exploiting two critical vulnerabilities in WordPress that, when chained, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The attacks are being fueled by the ready availability of numerous proof-of-concept exploits for the two bugs, identified as CVE-2026-60137 and CVE-2026-63030. Researchers at Searchlight Cyber discovered the flaws using GPT-5.6 Sol Ultra during vulnerability research and have dubbed the exploit chain "WP2Shell." The flaws affect tens — and potentially even hundreds – of millions of WordPress sites using default install configurations worldwide, giving attackers a vast pool of targets to try and exploit. And given the speed and scale of exploitation, organizations that have not yet patched have a a high likelihood of being compromised already: "Defenders need to inspect their WordPress instances for new administrator accounts, malicious plug-ins, or other suspicious files, regardless of whether they’ve patched," says Jake Knott, principal security researcher at watchTowr. Related:ClickFix's Mushrooming Ecosystem Demands New Defense Tactics WP2Shell: A Dangerous Cyberattack Duo CVE-2026-60137 is an SQL injection vulnerability in WordPress Core that allows an attacker to manipulate database queries and access data that should not be exposed. As a standalone flaw, it can be exploited only by an authenticated user. However, it becomes reachable without authentication when chained with CVE-2026-63030, a logic flaw in WordPress's Batch REST API, which lets applications bundle multiple requests, such as creating, updating, or retrieving content, into one API call. The bug has to do with a mismatch between how the batch endpoint validates requests and how it later executes them. An attacker can exploit this misalignment to sneak a malicious request past checks that would normally require a valid login. In a chained exploit, the two flaws allow an unauthenticated attacker with no login credentials to gain full RCE on a default WordPress install. The situation showcases the potential malicious power of AI, says Adam Kues, security researcher at Searchlight Cyber. He says GPT 5.6 Sol Ultra helped find the vulnerabilities and develop the exploit chain in a matter of just 10 hours. "I make no general claims, but I can say with complete confidence that no security researcher could have found and completed this exploit chain in 10 hours without AI." Kues wrote. "Even if I gave them the original bug and asked them to exploit it for RCE, I'm not sure it would be possible in that timeframe." Related:GigaWiper Lets Threat Actors Choose Their Own Destructive Attack Potentially Wide Impact on WordPress Sites The vulnerabilities affect WordPress versions 6.9.0 - 6.9.4 and 7.0.0 - 7.0.1. WordPress issued a security update on July 17 that addresses both vulnerabilities. "Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions," WordPress said. In a blog post, VulnCheck said it had verified more than two-dozen unique PoC exploits targeting WP2Shell as of Sunday, July 19, or barely two days after initial bug disclosure. "Affected users should update to a fixed version of WordPress as soon as possible, given the overwhelming likelihood that various public exploits and large-scale exploitation will follow the high-profile disclosure," VulnCheck said. WatchTowr's Knott says the company has been keeping a close eye on WP2Shell exploit activity since Friday via its Attacker Eye honeypot network. By the early hours of Saturday morning (UTC), attackers were well underway exploiting the two flaws, initially using public exploit code to exfiltrate hashed credentials, and then executing code remotely on vulnerable systems as additional details became available. "Once the vulnerabilities were publicly disclosed, reproducing them with the help of frontier AI models was only a matter of time and tokens," he says, pointing to how watchTowr was able to trivially reproduce CVE-2026-63030 within minutes of disclosure, and CVE-2026-60137 with some additional effort. Related:Turning the Tables on Email Scammers With 'ScamBuster' Tens of Thousands of Exploit Attempts Knott says watchTowr's honeypots have recorded tens of thousands of exploitation attempts and more than 100 backdoor accounts created by different threat actors using variations of public tooling. The attacks have been indiscriminate and opportunistic in nature and have impacted organizations of every size and across every vertical. "Once a backdoor administrator account was created, attackers deployed fake WordPress plug-ins to gain Remote Code Execution, exfiltrate credentials or secrets, or download additional tooling to further compromise the system. In one case, we watched a threat actor repeatedly attempt to pull down Overlord RAT, a Golang-based remote access Trojan," Knott says. In comments to Dark Reading, Patrick Munch, chief security officer at Mondoo, says the combination of a SQL injection vulnerability with an RCE bug makes WP2Shell an especially attractive proposition for attackers. “SQLi on its own gets you into the WordPress database. RCE gets you the whole server," he says, "Put them and a bug that 'only' leaks data, and you end up with a web shell on the host." What makes the two new vulnerabilities so attractive, Munch says, is that it they allow attackers to skip every step defenders usually get to interrupt: "No stolen password, no phished user, no vulnerable plug-in. Just one anonymous request to a stock install. That also means exploitation is a script, not a campaign, so attackers can sweep the entire Internet for targets." About the Author Jai Vijayan Contributing Writer Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies. Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders. Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications. His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars 0-Day to 10x Discovery: Security at the Speed of Mythos When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI Securing the AI Era: Shadow AI, AI Agents, and Why AI Detection and Response Changes Everything Practical Zero Trust Implementation on a Budget in the Age of Mythos More Webinars You May Also Like CYBERATTACKS & DATA BREACHES Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days by Jai Vijayan FEB 03, 2026 CYBERATTACKS & DATA BREACHES CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks by Rob Wright DEC 04, 2025 CYBERATTACKS & DATA BREACHES Deja Vu: Salesforce Customers Hacked Again, Via Gainsight by Nate Nelson NOV 21, 2025 CYBERATTACKS & DATA BREACHES Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business by Robert Lemos OCT 03, 2025 Editor's Choice VULNERABILITIES & THREATS Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes byJai Vijayan JUL 14, 2026 5 MIN READ PERIMETER 6 GHz Wi-Fi Flaws Could Disrupt Critical Systems byAlexander Culafi JUL 14, 2026 4 MIN READ CYBERSECURITY OPERATIONS 'Yellow Teams' Are Defining the Future of AI Security byNate Nelson JUL 13, 2026 6 MIN READ Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget,