CyberSecurity News
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
AI summary
Attackers are exploiting two critical WordPress vulnerabilities that allow for unauthenticated remote code execution and complete website compromise. These vulnerabilities are referred to as wp2shell and are tracked as CVE-2026-63030 and CVE-2026-60137. Exploitation of these flaws has been observed, with successful attacks already occurring by early Saturday morning UTC. The combination of the two vulnerabilities enables attackers to gain control of vulnerable websites. The public availability of an exploit is contributing to the growth of exploitation attempts. Mass scanning for vulnerable websites is underway.
Vulnerabilities mentioned
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

