Hackers Exploit Newly Patched WordPress Vulnerabilities

Hackers Already Exploiting Newly Patched WordPress Flaws, Researchers Warn

Hackers Already Exploiting Newly Patched WordPress Flaws, Researchers Warn

Attackers are exploiting two recently patched vulnerabilities affecting WordPress core software. Image: Deng Xiang/Unsplash

Security researchers warn hackers are actively exploiting two patched WordPress Core vulnerabilities that could let attackers fully compromise unpatched websites.

Jul 21, 2026

Hackers are already exploiting two newly patched WordPress vulnerabilities, exposing millions of websites that have yet to install the latest security updates to potential takeover.

The attack chain, dubbed WP2Shell, combines two WordPress Core vulnerabilities to achieve pre-authentication remote code execution, allowing attackers to run malicious code without first logging in.

The vulnerabilities are so severe that WordPress has released patched versions and enabled automatic security updates. Yet security researchers are warning that millions of the platform websites remain vulnerable, with Security firm WatchTowr saying “it has already seen in-the-wild exploitation” of the vulnerabilities, according to BleepingComputer.

That leaves the responsibility now on the shoulders of site owners who have yet to update their websites and, at the same time, serves as a reminder to all of the importance of treating security updates as a priority.

Two vulnerabilities: a single catastrophic attack

Alone, each vulnerability tracked as CVE-2026-63030 and CVE-2026-60137 can be exploited individually. Chained together, both can allow an attacker to fully compromise a website without ever needing to get authenticated.

According to BleepingComputer, both vulnerabilities were discovered by Adam Kues, a security researcher at Searchlight Cyber. He dubbed the attack WP2Shell, a name derived from its ability to allow an attacker to execute arbitrary shell commands on a vulnerable website.

CVE-2026-63030, rated critical, is a flaw in WordPress’s Batch REST API that can cause the software to misinterpret certain grouped API requests. Because of this confusion, WordPress may apply the wrong security checks, allowing specially crafted requests to reach parts of the system they shouldn’t.

CVE-2026-60137, on the other hand, has a moderate rating and can cause an SQL injection.

Quoting cybersecurity consultant Daniel Card, TechCrunch estimates that roughly 90 million websites remain directly exposed to the exploit chain, while more than 400 million sites are believed to be running WordPress versions within the affected release ranges. Not all of those sites are necessarily vulnerable, but the figures illustrate the attack’s potentially broad reach.

Advertisement

A rare kind of WordPress attack

What makes WP2Shell particularly concerning is that it targets WordPress Core rather than a third-party plugin.

Most WordPress-based attacks making headlines have usually been caused by plugins that site owners use on their websites. However, CVE-2026-63030 and CVE-2026-60137 affect the WordPress software itself.

That means even websites running a clean, default WordPress installation could be vulnerable.

Must-read security coverage

Why patching quickly matters

A bigger lesson from this isn’t related to WordPress. It is that threat actors have learned to capitalize on security updates released to exploit users still running unpatched software. For everyone, this indicates that software updates should no longer be treated as a periodic activity.

Despite a patch existing and WordPress enabling automatic updates, reports of live exploitation suggest that many site owners didn’t catch it, suggesting that many affected sites either had not yet installed the updates or were not receiving automatic security patches. If your website runs WordPress, the platform urges you to update your software without delay.

Our recommendation is to set up auto-updates where necessary, or, when that’s impossible, set up monitoring systems that alert you when an update becomes available. Those who run critical software in production may understandably want to ensure an update won’t break their systems, but, if possible, a test update can be applied on a non-production system to validate its quality.

Advertisement

The reason is simple: cybersecurity has become a battle over execution speed, and even companies like Microsoft have begun urging customers to update their devices within three days because, at the end of the day, the fastest party often wins.

As attackers increasingly weaponize newly disclosed vulnerabilities within days—or even hours—of patches becoming available, rapid patch management has become one of the most effective defenses organizations have against compromise.

Other News: Microsoft is reportedly developing an AI-powered security tool that could undercut Anthropic’s Mythos by automatically finding and fixing software vulnerabilities at a lower cost for enterprise customers.

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.