preloader

· digital-security devops wordpress cloud europe

wp2shell: A Zero-Click WordPress Core Flaw Is Already Under Mass Attack, Even on Sites With No Plugins

Source: The Hacker News / Rapid7 / WordPress.org

Researchers disclosed a new WordPress Core vulnerability chain on 17 July that deserves urgent attention from anyone running a WordPress site: wp2shell combines a SQL injection in the author__not_in parameter of WP_Query, tracked as CVE-2026-60137, with a REST API batch-route confusion issue, tracked as CVE-2026-63030. Chained together, the two flaws let an anonymous, unauthenticated attacker achieve remote code execution against a completely stock WordPress installation, with no plugins required and no login of any kind.

No conditions to meet, and WordPress knows it

WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected; fixes shipped the same day the flaw was disclosed, in versions 6.9.5 and 7.0.2. Given the severity and the fact the attack has no preconditions, WordPress.org took the unusual step of forcing the update onto every site running an affected version through its auto-update system, rather than waiting for site owners to act. That decision tells you how the WordPress security team itself rated the risk.

Attackers did not wait

Exploitation began within roughly a day of disclosure, and by the weekend of 19 to 20 July, researchers had verified more than two dozen distinct working proof-of-concept exploits circulating, alongside a public scanning tool that lets anyone, attacker or defender, check whether a given site is still vulnerable. That is a very short window between a patch existing and mass exploitation becoming trivial to carry out.

Forced updates do not cover every site

Auto-updates are a real safety net, but they are not universal. Sites on managed hosts with update policies disabled, self-hosted installations with modified core files, environments pinned to a specific WordPress version for compatibility reasons, and anything running behind infrastructure that was never configured to receive WordPress.org’s forced-update signal can all remain exposed well after the patch existed. WordPress still runs a very large share of business and e-commerce websites across Europe, which makes an unauthenticated, no-plugin-required RCE in Core a continent-wide problem, not a niche one.

If you run WordPress sites and are not certain every one of them actually received the 6.9.5 or 7.0.2 update, or if you suspect one may already be compromised, contact Excello Digital. We audit and harden WordPress environments for European businesses and can confirm whether your sites are patched, exposed, or already showing signs of exploitation.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!