WordPress Flaws Leave Millions of Sites Vulnerable to Full Takeover

Image Courtesy : commons.wikimedia.org


Two newly disclosed WordPress core vulnerabilities—now collectively known as WP2Shell—have exposed tens of millions of websites to unauthenticated remote code execution, enabling attackers to seize complete control of affected installations. Within just days of disclosure, security firms reported widespread exploitation attempts, fueled by publicly available proof‑of‑concept code and the massive global footprint of WordPress.

The WP2Shell exploit chain combines CVE‑2026‑60137, a high‑severity SQL injection flaw, with CVE‑2026‑63030, a critical logic flaw in WordPress’s Batch REST API. Individually, the SQL injection bug requires authentication—but when chained with the REST API flaw, attackers can bypass login requirements entirely. This allows anonymous threat actors to manipulate database queries and execute arbitrary code on a default WordPress installation with no plugins installed.

Researchers at Searchlight Cyber discovered the vulnerabilities using advanced AI‑assisted tooling, noting that the exploit chain could be developed in hours—far faster than traditional manual research. WordPress versions 6.9.0–6.9.4 and 7.0.0–7.0.1 are confirmed vulnerable, prompting WordPress.org to issue emergency patches in 6.9.5, 7.0.2, and 6.8.6, along with forced auto‑updates due to the severity of the threat.

Cybersecurity firms including Patchstack, Hexastrike, and WatchTowr have already observed active exploitation in the wild. Honeypot data shows attackers rapidly scanning for vulnerable sites, with some firms assisting in incident response for compromised installations. Estimates suggest that tens of millions of WordPress sites were initially at risk, with one projection indicating that roughly 90 million installations may still be vulnerable depending on patch adoption rates.

Security experts warn that organizations should not assume patching alone guarantees safety. Because exploitation began almost immediately, administrators are urged to inspect their sites for signs of compromise—such as unauthorized admin accounts, malicious plugins, or suspicious files—even if updates have already been applied.

The WP2Shell incident underscores a growing trend: AI‑accelerated vulnerability discovery is shrinking the window between disclosure and exploitation. For millions of WordPress site owners, rapid patching and thorough post‑update audits are now essential steps in preventing full site takeover.

Naya Kelise

Naya Kelise is Sr. Staff Writer for many ADE Media brands including Gadget Geeksters, and travels between and publishes for the Houston and Miami channels. As an urban explorer, she values maneuvering the bustling beautiful city of Miami and surrounding areas to provide the most shareable digital content to natives, tourists, and city enthusiasts locally around Miami.

Post a Comment

Previous Post Next Post