CyberSecurity News
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
AI summary
Attackers are exploiting two vulnerabilities to target WordPress sites, with exploit attempts being made just days after the issues were disclosed. The vulnerabilities are being chained together to launch remote takeover attempts against a large number of sites. This attack surface is one of the largest on the internet, putting millions of sites at risk. The vulnerabilities in question have been identified, but the pace of exploitation has been rapid.
Vulnerabilities mentioned
WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection when a plugin or theme passes untrusted input to the parameter.
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query SQL Injection (CVE-2026-60137), could allow an attacker to perform SQL Injection and achieve Remote Code Execution.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to Dark Reading.

