Home Risk & Resilience Critical WordPress Vulnerabilities Trigger Widespread Scanning And Remote Code Execution Attacks

Critical WordPress Vulnerabilities Trigger Widespread Scanning And Remote Code Execution Attacks

0
Critical WordPress Vulnerabilities Trigger Widespread Scanning And Remote Code Execution Attacks

Attackers have started actively exploiting two critical WordPress vulnerabilities that can be chained together to achieve unauthenticated remote code execution and complete compromise of vulnerable websites. The flaws, tracked as CVE 2026 63030 and CVE 2026 60137, have been collectively named wp2shell by security researchers. According to watchTowr, successful exploitation began within hours of public exploit code becoming available. Early attacks focused on extracting hashed credentials before progressing to full remote code execution as more technical details were disclosed. Jake Knott, Principal Security Researcher at watchTowr, said the company has observed widespread exploitation affecting organizations of all sizes and industries. Telemetry collected by KEVIntel has linked at least 13 unique IP addresses from Switzerland, Germany, the United Kingdom, Indonesia, Lithuania, the Netherlands, and Singapore to exploitation attempts targeting CVE 2026 63030.

The exploit chain was discovered by Searchlight Cyber using OpenAI GPT 5.6 Sol over approximately ten hours of analysis. Researchers said the attack can compromise default WordPress installations released since December 2025 without requiring authentication or installed plugins. Due to the severity of the issue, detailed technical information has not been publicly released. Cloudflare explained that CVE 2026 63030 enables unauthenticated remote code execution when persistent object cache is not enabled, while CVE 2026 60137 is an SQL injection vulnerability affecting WordPress version 6.8 and later. The remote code execution component impacts version 6.9 onward. Ben Marr, Security Engineer at Intruder, explained that the attack chain begins with a route confusion flaw in the WordPress REST API batch endpoint, allowing attackers to bypass authentication and invoke internal handlers without permission checks. The vulnerability is further enabled by improper sanitization of the author__not_in parameter in WP_Query, making it possible for attackers to manipulate database queries and potentially gain unauthorized access or modify stored data.

Security data published by Google owned Wiz showed that when the vulnerabilities were disclosed, approximately 60 percent of organizations using WordPress had at least one vulnerable instance, while 25 percent had an exposed vulnerable server accessible from the internet. Those figures have declined as organizations continue applying available fixes. Researchers have already documented multiple post exploitation activities carried out by attackers after compromising websites. These include uploading malicious plugins, identifying administrator usernames and email addresses, conducting local file inclusion attacks to obtain database credentials and authentication keys, accessing administrator panels, and installing lightweight PHP web shells that enable persistent remote code execution. Wiz researchers Shahar Dorfman and Gili Tikochinski also observed large scale scanning campaigns that appeared to identify vulnerable servers without immediately launching additional attacks. While researchers have not yet confirmed lateral movement or large scale data exfiltration, investigations remain ongoing as security teams continue monitoring attack activity.

WatchTowr reported that the public release of exploit code has triggered indiscriminate internet wide scanning, with its honeypot systems recording tens of thousands of exploitation attempts. Researchers have also identified a 150 KB web shell disguised as a legitimate WordPress security plugin named CMSmap. The malicious software functions as a complete attack platform, providing capabilities including file management, database access, port scanning, batch code injection, and privilege escalation through multiple techniques such as MySQL User Defined Function exploitation. More than 100 unauthorized administrator accounts have reportedly been created on compromised websites, enabling attackers to deploy fake WordPress plugins, execute malicious code, and install additional malware. In at least one documented incident, attackers repeatedly attempted to deploy Overlord RAT, a Golang based remote access trojan, after gaining access. Security researchers strongly recommend that WordPress administrators inspect their environments for newly created administrator accounts, suspicious plugins, unknown files, and other indicators of compromise, even after applying the latest security updates, to ensure attackers have not established persistent access.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.