Site icon TechloMedia

Critical WordPress ‘wp2shell’ Flaws Now Have Public Exploits, Update Your Site Immediately

WordPress Hosting

WordPress website owners should update their sites as soon as possible. Security researchers have warned that public exploits are now available for the critical “wp2shell” vulnerabilities, making it easier for attackers to target unpatched websites.

The attack chain combines two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137. Together, they can allow an attacker to execute malicious code on a vulnerable WordPress website without needing to log in first.

The vulnerabilities affect WordPress 6.9.x and 7.0.x. WordPress has already released security updates in versions 6.9.5 and 7.0.2 to fix the issue.

According to Searchlight Cyber, the flaws can be exploited on a default WordPress installation without requiring any plugins. Since WordPress powers hundreds of millions of websites worldwide, the impact could be significant if site owners delay updating.

The first flaw is a REST API batch-route confusion bug introduced in WordPress 6.9. The second is an SQL injection vulnerability in the author__not_in parameter of WP_Query. Individually, they are dangerous, but together they can create a complete remote code execution attack.

The SQL injection flaw also affects WordPress 6.8.x, but it cannot be chained into remote code execution because the REST API vulnerability does not exist in that version.

Because of the severity of the issue, the WordPress security team has enabled forced automatic security updates for supported websites running affected versions. However, administrators should still verify that their sites have been updated successfully.

Searchlight Cyber has delayed publishing full technical details to give website owners time to patch. The company has instead launched a website that allows administrators to check whether their WordPress installation is vulnerable.

For websites that cannot be updated immediately, researchers recommend temporarily blocking anonymous access to the WordPress REST API or blocking the affected batch API endpoints using a Web Application Firewall. These are only temporary protections and should not replace installing the official security update.

Cloudflare has also rolled out WAF protections for both vulnerabilities across all of its plans, including free accounts. These rules can block known exploit attempts, but Cloudflare has also reminded users that firewall protection is not a substitute for patching.

The biggest concern is that multiple proof-of-concept exploits have already been published on GitHub. Some of them extract password hashes before attempting to crack administrator passwords, while others claim to achieve remote code execution without requiring any administrator credentials.

Security researchers have also reported the first signs of attackers exploiting these flaws in real-world attacks. This often happens when public exploit code becomes available, as cybercriminals quickly begin scanning the internet for vulnerable websites.

If your website is running WordPress 6.9.0 to 6.9.4 or WordPress 7.0.0 to 7.0.1, updating to WordPress 6.9.5 or 7.0.2 should be your highest priority. Even if your site is protected by a firewall, installing the official patch remains the only reliable way to eliminate the risk.

Keeping your WordPress website secure requires more than just installing updates. Regular security audits, malware scanning, performance optimization, backups, and timely patch management are equally important. Techlomedia Internet offers professional WordPress development, maintenance, migration, performance optimization, and security services to help businesses keep their websites fast, secure, and protected from the latest cyber threats. If you need expert assistance with your WordPress website, feel free to get in touch with the Techlomedia team.

Exit mobile version