Executive Summary
In July 2026, two critical vulnerabilities in WordPress, identified as CVE-2026-63030 and CVE-2026-60137, collectively termed 'wp2shell,' were disclosed. These flaws enable unauthenticated remote code execution (RCE) on default WordPress installations, allowing attackers to fully compromise affected websites. Exploitation began shortly after public disclosure, with attackers deploying persistent webshells and exfiltrating hashed credentials. The vulnerabilities impact WordPress versions 6.9.0 through 7.0.1, with patches available in versions 6.9.5 and 7.0.2. Organizations are urged to apply these updates promptly to mitigate the risk of exploitation.
The rapid exploitation of wp2shell underscores the critical need for timely patch management and robust security measures. With WordPress powering a significant portion of the web, the widespread impact of these vulnerabilities highlights the importance of proactive vulnerability management and continuous monitoring to safeguard digital assets.
Why This Matters Now
The wp2shell vulnerabilities are actively being exploited in the wild, posing an immediate threat to millions of WordPress sites. Organizations must prioritize patching and implementing security controls to prevent potential breaches and data exfiltration.
Attack Path Analysis
Attackers exploited the wp2shell vulnerability chain to gain unauthenticated remote code execution on vulnerable WordPress installations. They escalated privileges by creating administrative accounts through SQL injection. Lateral movement was achieved by deploying webshells and malicious plugins to maintain persistent access. Command and control were established via these webshells, allowing remote management of compromised servers. Exfiltration involved unauthorized access to sensitive data stored on the servers. The impact included defacement, data theft, and potential deployment of additional malware.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited the wp2shell vulnerability chain (CVE-2026-63030 and CVE-2026-60137) to gain unauthenticated remote code execution on vulnerable WordPress installations.
Related CVEs
CVE-2026-63030
CVSS 9.8A REST API batch endpoint route confusion in WordPress versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 allows unauthenticated attackers to perform SQL Injection and achieve Remote Code Execution when chained with CVE-2026-60137.
Affected Products:
WordPress WordPress – 6.9.0, 6.9.1, 6.9.2, 6.9.3, 6.9.4, 7.0.0, 7.0.1
Exploit Status:
exploited in the wildCVE-2026-60137
CVSS 5.9An SQL injection vulnerability in the author__not_in parameter of WP_Query in WordPress versions 6.8.0 through 6.8.5, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 allows attackers to perform SQL Injection, which can be chained with CVE-2026-63030 to achieve Remote Code Execution.
Affected Products:
WordPress WordPress – 6.8.0, 6.8.1, 6.8.2, 6.8.3, 6.8.4, 6.8.5, 6.9.0, 6.9.1, 6.9.2, 6.9.3, 6.9.4, 7.0.0, 7.0.1
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Command and Scripting Interpreter: Windows Command Shell
Valid Accounts
Account Discovery: Local Account
Impair Defenses: Disable or Modify Tools
Data Destruction
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Access Privileges
Control ID: 500.07
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
WordPress wp2shell RCE vulnerabilities enable complete website compromise through unauthenticated attacks, requiring immediate patching and enhanced egress security controls.
Online Publishing
Mass WordPress exploitation threatens content management systems with remote code execution, demanding zero trust segmentation and inline intrusion prevention capabilities.
Media Production
WordPress-based media platforms face critical RCE risks from CVE-2026-63030/60137 exploitation, necessitating encrypted traffic monitoring and anomaly detection systems.
Marketing/Advertising/Sales
WordPress websites used for campaigns vulnerable to unauthenticated remote code execution attacks, requiring multicloud visibility and threat detection implementations.
Sources
- WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanninghttps://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.htmlVerified
- WordPress 7.0.2 Releasehttps://wordpress.org/news/2026/07/wordpress-7-0-2-release/Verified
- WordPress Core 'wp2shell' RCE flaws get public exploits, patch nowhttps://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/Verified
- WordPress wp2shell Vulnerabilities Exploited in the Wild (CVE-2026-63030 & CVE-2026-60137)https://threatprotect.qualys.com/2026/07/20/wordpress-wp2shell-vulnerabilities-exploited-in-the-wild-cve-2026-63030-cve-2026-60137/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit vulnerabilities may be constrained by enforcing strict workload isolation and identity-based access controls.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges could be limited by enforcing least-privilege access and segmenting administrative functions.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement within the environment would likely be restricted by controlling east-west traffic and enforcing segmentation.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels could be constrained by providing comprehensive visibility and control over multicloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely be limited by enforcing strict egress policies and monitoring outbound traffic.
The overall impact of the attack could be reduced by limiting the attacker's ability to move laterally, escalate privileges, and exfiltrate data.
Impact at a Glance
Affected Business Functions
- Website Content Management
- E-commerce Transactions
- User Authentication
Estimated downtime: 7 days
Estimated loss: $50,000
Potential exposure of user credentials, payment information, and personal data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict unauthorized access and limit lateral movement within the network.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts targeting known vulnerabilities.
- • Utilize Cloud Firewall (ACF) to enforce egress filtering and prevent unauthorized outbound traffic.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Ensure regular patching and updates of WordPress installations to mitigate known vulnerabilities.



