< Back to all clusters
[TECHNOLOGY] · Portugal, Poland, Italy, Germany, Netherlands · 17 sources

started · updated

WordPress WP2Shell flaw exploited, millions of sites urged to update

Security researcher Adam Kues of Searchlight Cyber discovered a critical WordPress Core vulnerability using OpenAI's GPT‑5.6, naming it WP2Shell. The flaw combines two CVEs – CVE‑2026‑63030 (REST API batch‑route confusion) and CVE‑2026‑60137 (SQL‑injection in the WP_Query author__not_in parameter) – to enable unauthenticated remote code execution on default WordPress installations.

The defects affect WordPress versions 6.9.0‑6.9.4, 7.0.0‑7.0.1 (and the SQL‑injection also impacts 6.8.0‑6.8.5). An emergency patch was released on 17 July 2026, with forced automatic updates enabled where possible. National cyber agencies in Portugal, Poland, the Netherlands, Germany, Italy, Slovakia, Hungary and the United States issued alerts, warning that millions of sites remain vulnerable. Estimates suggest up to 90 million installations (about 15 % of the 400 million sites running the affected versions) could be compromised.

Active exploitation was reported within hours of disclosure, with threat actors deploying back‑doors, stealing credentials and installing malicious plugins. Experts advise administrators to upgrade immediately to WordPress 6.9.5, 7.0.2 (or later) and to enable automatic updates, implement WAF rules, and use persistent object caching to mitigate the attack chain.

Sources