Updated
Updated · The Hacker News · Jul 21
Searchlight Cyber Discloses 2-CVE WordPress Core RCE as PoC Exploits Emerge
Updated
Updated · The Hacker News · Jul 21

Searchlight Cyber Discloses 2-CVE WordPress Core RCE as PoC Exploits Emerge

3 articles · Updated · The Hacker News · Jul 21

Summary

  • WordPress Core can be turned into anonymous remote code execution on a standard installation by chaining CVE-2026-63030 and CVE-2026-60137, with no plugin or special condition required.
  • Searchlight Cyber said the chain abuses REST API batch-route confusion plus a core SQL injection flaw, letting a single unauthenticated request escalate into code execution.
  • watchTowr said proof-of-concept exploits are already circulating and it is seeing early signs of in-the-wild exploitation, raising the risk for sites that are not auto-patched by hosting providers.
  • Hundreds of millions of websites could be exposed, and defenders were urged to patch quickly, investigate for prior compromise, and remove any backdoors that may have been dropped before fixes were applied.

Insights

If security patches are instantly weaponized by AI, does releasing them now do more harm than good?
With AI giving state-level cyber power to anyone, is a truly unhackable system now impossible?

2026 WordPress "wp2shell" Vulnerabilities (CVE-2026-60137 & CVE-2026-63030): Widespread Exploitation and Emergency Mitigation Guide

Overview

As of July 21, 2026, the digital landscape faces a major threat due to the widespread exploitation of two critical WordPress vulnerabilities, known as WP2Shell. These flaws are being actively targeted, with proof-of-concept exploits readily available, putting a large segment of WordPress users at risk. The confirmed attacks focus on specific WordPress versions, making immediate action essential. Site owners are urged to secure their installations without delay, as attackers can easily compromise unpatched systems. The urgency is driven by the rapid spread and active exploitation, highlighting the need for prompt patching and strong security measures.

...