Executive Summary
In July 2026, two critical vulnerabilities in WordPress Core, identified as CVE-2026-60137 and CVE-2026-63030, were disclosed. When exploited together, these flaws, collectively termed 'WP2Shell,' allow unauthenticated remote code execution on default WordPress installations. CVE-2026-60137 is an SQL injection vulnerability in the 'author__not_in' parameter of WP_Query, while CVE-2026-63030 is a REST API batch-route confusion issue. Attackers have rapidly developed and disseminated proof-of-concept exploits, leading to widespread exploitation attempts against millions of WordPress sites worldwide. Organizations are urged to update to the latest WordPress versions immediately to mitigate this threat. (vulncheck.com)
The rapid exploitation of WP2Shell underscores the increasing sophistication and speed of threat actors in leveraging newly disclosed vulnerabilities. This incident highlights the critical importance of timely patching and proactive security measures to protect web assets from emerging threats.
Why This Matters Now
The WP2Shell vulnerabilities are actively being exploited in the wild, posing an immediate risk to millions of WordPress sites. Organizations must prioritize patching to prevent potential data breaches and service disruptions.
Attack Path Analysis
Attackers exploited the WP2Shell vulnerability chain to gain unauthenticated remote code execution on WordPress sites. They escalated privileges by creating new administrator accounts. Subsequently, they moved laterally within the compromised environment to access additional resources. Attackers established command and control channels to maintain persistent access. They exfiltrated sensitive data from the compromised servers. Finally, they deployed malicious plugins to maintain access and potentially disrupt services.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited the WP2Shell vulnerability chain (CVE-2026-63030 and CVE-2026-60137) to gain unauthenticated remote code execution on WordPress sites.
Related CVEs
CVE-2026-60137
CVSS 5.9WordPress versions 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 do not properly sanitize the author__not_in parameter of WP_Query, allowing SQL Injection when untrusted input is passed to the parameter.
Affected Products:
WordPress WordPress – 6.8.x before 6.8.6, 6.9.x before 6.9.5, 7.0.x before 7.0.2
Exploit Status:
exploited in the wildCVE-2026-63030
CVSS 9.8WordPress versions 6.9.x before 6.9.5 and 7.0.x before 7.0.2 are affected by a REST API batch endpoint route confusion issue which, when combined with CVE-2026-60137, allows an attacker to perform SQL Injection and achieve Remote Code Execution.
Affected Products:
WordPress WordPress – 6.9.x before 6.9.5, 7.0.x before 7.0.2
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
SQL Stored Procedures
Command and Scripting Interpreter: Windows Command Shell
Valid Accounts
Application Layer Protocol: Web Protocols
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components and software are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity Management and Access Control
Control ID: Pillar 1: Identity
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
WordPress sites hosting software companies face critical RCE vulnerabilities enabling complete system compromise, threatening source code, intellectual property, and customer data through web application exploitation.
E-Learning
Educational platforms using WordPress vulnerable to unauthenticated remote takeover, compromising student data, course materials, and learning management systems through chained SQL injection attacks.
Media Production
Media companies with WordPress-based websites exposed to immediate exploitation enabling content manipulation, credential theft, and deployment of backdoors affecting editorial integrity and operations.
Marketing/Advertising/Sales
Marketing agencies using WordPress face widespread exploitation attempts targeting client data, campaign materials, and customer databases through automated RCE attacks requiring immediate patching.
Sources
- 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeoverhttps://www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeoverVerified
- NVD - CVE-2026-60137https://nvd.nist.gov/vuln/detail/CVE-2026-60137Verified
- NVD - CVE-2026-63030https://nvd.nist.gov/vuln/detail/CVE-2026-63030Verified
- WordPress 7.0.2 Release – WordPress Newshttps://wordpress.org/news/2026/07/wordpress-7-0-2-release/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is relevant to this incident as it could have limited the attacker's ability to escalate privileges, move laterally, establish command and control channels, and exfiltrate data, thereby reducing the overall impact of the compromise.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent the initial exploitation of the WP2Shell vulnerability, it could limit the attacker's ability to escalate privileges and move laterally within the environment.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could limit the attacker's ability to escalate privileges by enforcing strict access controls and minimizing the scope of accessible resources.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could limit the attacker's ability to move laterally by enforcing strict segmentation and monitoring internal traffic patterns.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could limit the attacker's ability to establish command and control channels by monitoring and controlling outbound traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could limit the attacker's ability to exfiltrate sensitive data by controlling and monitoring outbound data transfers.
Aviatrix Zero Trust CNSF could limit the attacker's ability to deploy malicious plugins by enforcing strict access controls and monitoring for unauthorized changes.
Impact at a Glance
Affected Business Functions
- Website Content Management
- E-commerce Transactions
- User Authentication
Estimated downtime: 7 days
Estimated loss: $50,000
Potential exposure of user credentials and personal information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict access and limit lateral movement within the network.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts targeting known vulnerabilities.
- • Utilize Cloud Firewall (ACF) to enforce egress filtering and prevent unauthorized outbound traffic.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
- • Regularly update and patch WordPress installations to mitigate known vulnerabilities.



