Two chained WordPress core flaws (WP2Shell) let unauthenticated attackers take over sites with no plugin needed
Security researchers at Searchlight Cyber disclosed two chained WordPress core vulnerabilities, CVE-2026-60137 and CVE-2026-63030, that let an anonymous attacker achieve remote code execution on a stock install with no plugins. WordPress patched versions 6.9.0-6.9.4 and 7.0.0-7.0.1 with emergency releases 6.9.5 and 7.0.2 on Friday, per SecurityWeek and The Hacker News, and security firms including Patchstack and WatchTowr report exploitation already underway.
Two chained vulnerabilities in WordPress core itself, dubbed WP2Shell and tracked as CVE-2026-60137 (SQL injection) and CVE-2026-63030 (remote code execution), let an unauthenticated attacker take over a stock WordPress install with no plugins and no preconditions, according to security firm Searchlight Cyber. The flaws affected WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. WordPress released emergency patches 6.9.5 and 7.0.2 this past Friday and enabled forced auto-updates given the severity. Security firms Patchstack, Hexastrike and WatchTowr have confirmed in-the-wild exploitation attempts, with WatchTowr CEO Benjamin Harris warning that hosting providers without auto-patching will bear the damage. Source: SecurityWeek, The Hacker News.