Unauthenticated attackers are exploiting critical remote code execution vulnerabilities in WordPress core known as WP2Shell [1].

These flaws are significant because they allow unauthorized users to take control of websites without needing login credentials. Because WordPress powers a vast portion of the internet, these vulnerabilities create a massive surface area for global cyberattacks.

The vulnerabilities are identified as CVE-2026-60137 [1] and CVE-2026-63030 [1]. According to reports, these flaws allow for unauthenticated remote code execution, a high-value target for attackers seeking to compromise servers [3, 4].

Security researchers said that the exploitation began shortly after the vulnerabilities were disclosed in early July 2026 [1, 3]. While some reports focus on the release of public exploits [2], other evidence indicates that active exploitation in the wild is already occurring across worldwide installations [1, 2].

WordPress has released patches to address these security gaps. The fixes are included in WordPress versions 6.9.5 and 7.0.2 [3]. Site administrators are urged to update their installations immediately to prevent potential breaches.

The WP2Shell vulnerabilities represent a critical failure in the core software that manages how the platform processes certain requests. By bypassing authentication, attackers can inject malicious code directly into the server environment. This level of access typically allows an attacker to steal sensitive data, deface websites, or install ransomware.

Attackers are exploiting critical remote code execution vulnerabilities in WordPress core known as WP2Shell.

The rapid transition from vulnerability disclosure to active exploitation highlights the speed at which threat actors monitor security advisories. Because these flaws exist in the WordPress core rather than a third-party plugin, the risk is systemic. Organizations that do not utilize automated updates are particularly vulnerable to this wave of attacks.