Executive Summary
In July 2026, a critical vulnerability chain known as "wp2shell" (CVE-2026-63030 and CVE-2026-60137) was discovered in WordPress Core, allowing unauthenticated remote code execution. Attackers exploited these flaws to deploy persistent webshells and install malicious plugins on vulnerable servers. The exploit leverages the WordPress REST API's batch-processing feature, enabling code execution without authentication. WordPress addressed the issue in versions 7.0.2, 6.9.5, and 6.8.6, prompting automatic security updates for supported installations.
The rapid emergence of proof-of-concept exploits and active exploitation underscores the urgency for organizations to update their WordPress installations promptly. This incident highlights the critical need for timely patch management and vigilant monitoring of web applications to prevent unauthorized access and potential data breaches.
Why This Matters Now
The wp2shell vulnerabilities are actively being exploited, posing immediate risks to unpatched WordPress sites. Organizations must prioritize updating their installations to prevent unauthorized access and potential data breaches.
Attack Path Analysis
Attackers exploited the wp2shell vulnerabilities (CVE-2026-63030 and CVE-2026-60137) to gain unauthorized access to WordPress installations. They escalated privileges by creating rogue administrator accounts. Lateral movement was not observed in this campaign. Attackers established command and control by deploying persistent webshells disguised as plugins. No data exfiltration was reported. The impact included unauthorized access and potential for further exploitation.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited the wp2shell vulnerabilities (CVE-2026-63030 and CVE-2026-60137) to gain unauthorized access to WordPress installations.
Related CVEs
CVE-2026-63030
CVSS 9.8A REST API batch endpoint route confusion issue in WordPress versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2, when combined with CVE-2026-60137, allows unauthenticated remote attackers to perform SQL Injection and achieve Remote Code Execution.
Affected Products:
WordPress WordPress – 6.9.x before 6.9.5, 7.0.x before 7.0.2
Exploit Status:
exploited in the wildCVE-2026-60137
CVSS 5.9Improper sanitization of the author__not_in parameter in WP_Query in WordPress versions 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 allows SQL Injection when untrusted input is passed to the parameter.
Affected Products:
WordPress WordPress – 6.8.x before 6.8.6, 6.9.x before 6.9.5, 7.0.x before 7.0.2
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Web Shell
Web Protocols
Local Accounts
Windows Command Shell
LSASS Memory
File and Directory Discovery
Disable or Modify Tools
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
WordPress core vulnerabilities enable webshell deployment and malicious plugin installation, critically impacting software development platforms requiring immediate patching and enhanced segmentation controls.
Marketing/Advertising/Sales
Web application exploits targeting WordPress sites threaten marketing platforms and customer-facing applications, requiring egress filtering and anomaly detection to prevent data exfiltration.
Media Production
Critical WordPress flaws expose content management systems to remote code execution attacks, compromising digital publishing workflows and requiring zero trust segmentation implementation.
Health Care / Life Sciences
WordPress webshell attacks threaten HIPAA-compliant patient portals and healthcare websites, requiring encrypted traffic monitoring and inline intrusion prevention to protect sensitive data.
Sources
- Critical wp2shell WordPress flaws exploited to install webshellshttps://www.bleepingcomputer.com/news/security/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells/Verified
- Exploitation in the Wild of wp2shellhttps://www.wiz.io/blog/wp2shell-cve-2026-63030-cve-2026-60137Verified
- WordPress 7.0.2 Releasehttps://wordpress.org/news/2026/07/wordpress-7-0-2-release/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to escalate privileges and establish command and control, thereby reducing the potential for further exploitation.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access may have been constrained, reducing the likelihood of unauthorized entry into the WordPress installations.
Control: Zero Trust Segmentation
Mitigation: The creation of rogue administrator accounts could have been restricted, limiting the attacker's ability to escalate privileges.
Control: East-West Traffic Security
Mitigation: While lateral movement was not observed, East-West Traffic Security could have further constrained any potential internal movement.
Control: Multicloud Visibility & Control
Mitigation: The establishment of command and control channels may have been detected and constrained, limiting the attacker's ability to maintain persistence.
Control: Egress Security & Policy Enforcement
Mitigation: Potential data exfiltration attempts could have been restricted, reducing the risk of unauthorized data transfer.
The overall impact of unauthorized access and potential exploitation could have been limited, reducing the attacker's ability to cause further harm.
Impact at a Glance
Affected Business Functions
- Website Content Management
- E-commerce Transactions
- User Authentication
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of user credentials and personal information stored in the WordPress database.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict unauthorized access and limit the spread of potential threats.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts targeting known vulnerabilities.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to unusual activities promptly.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent unauthorized data transfers.
- • Ensure regular updates and patch management to mitigate vulnerabilities like wp2shell.



