WP2Shell WordPress Flaws Under Active Exploitation

Two WordPress flaws called WP2Shell (CVE-2026-60137, CVE-2026-63030) are being exploited; patches 6.9.5 and 7.0.2 are available and forced auto-updates enabled.
Searchlight Cyber discovered two WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030. The flaws affect WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1. CVE-2026-60137 is a high-severity SQL injection issue and CVE-2026-63030 allows arbitrary code execution.
When an attacker chains the two flaws, an unauthenticated user can achieve remote code execution on a stock WordPress install without plugins. WordPress released fixes in versions 6.9.5 and 7.0.2 and enabled forced auto-updates for sites still on affected releases.
Cloudflare deployed detection and protection rules for customers with unpatched installations. Searchlight Cyber withheld full technical details to limit abuse, but proof-of-concept exploits have been published and are circulating.
Multiple security companies reported exploitation attempts in the wild. A WordPress security vendor observed attempts, and incident responders saw activity in honeypots. One responder reported it had assisted with incident response for several attacks.
Benjamin Harris, CEO of WatchTowr, warned: “This is going to hurt.” He noted AI-assisted tools have shortened the time between disclosure and weaponization, with proof-of-concept code appearing within hours of disclosure.
Administrators should upgrade immediately to WordPress 6.9.5 or 7.0.2 and confirm auto-updates applied. Teams should search for signs of compromise such as unexpected administrative accounts, modified files, or unknown code execution. Security vendors have released rules to detect exploitation, and incident responders recommend isolating affected sites and restoring from clean backups when necessary.
Because the chain can produce unauthenticated remote code execution on stock installs, sites without third-party plugins are included among those at risk. Some hosting providers will auto-patch, but many sites may remain unpatched and vulnerable.




