Close Menu
    What's Hot

    1,700 H.I.V. Treatment Sites Closed After Trump Aid Cuts, a Study Finds

    The Xteink X4 Pro could be the tiny e-reader of your dreams

    Why the world trusts China more than America

    Facebook X (Twitter) Instagram
    Trending
    • 1,700 H.I.V. Treatment Sites Closed After Trump Aid Cuts, a Study Finds
    • The Xteink X4 Pro could be the tiny e-reader of your dreams
    • Why the world trusts China more than America
    • Oil Buyers Battered by the Iran War Energy Crisis Race to Build Buffers
    • Halliday’s New Smart Glasses Skip the Camera
    • What’s in a Watch Shape?
    • Anthropic AI copyright lawsuit: Update as judge approves massive settlement and payout for authors
    • Don’t Overestimate America and China’s Importance by Jim O’Neill
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

    adminBy adminJuly 21, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
    Share
    Facebook Twitter LinkedIn Pinterest Email

    WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

    Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.

    The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell.

    “By the early hours of Saturday morning (UTC), successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public,” Jake Knott, principal security researcher at watchTowr, told The Hacker News in a statement.

    “From our vantage point across a global client base, we are seeing widespread impact of this vulnerability across organizations of every size and every vertical.”

    Telemetry data captured by KEVIntel shows that 13 unique IP addresses from Switzerland, Germany, the U.K., Indonesia, Lithuania, the Netherlands, and Singapore have been linked to the exploitation of CVE-2026-63030.

    The exploit chain, discovered by Searchlight Cyber using OpenAI GPT 5.6 Sol in over 10 hours, essentially allows unauthenticated attackers to gain remote code execution on default WordPress installations in any WordPress version released since December 2025. Technical details have been withheld in light of the severity of the issue.

    Cybersecurity

    “The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins,” Searchlight Cyber said.

    According to Cloudflare, CVE-2026-63030 enables unauthenticated remote code execution (RCE) only when persistent object cache is not in use. While the SQL injection vulnerability (CVE-2026-60137) is present from version 6.8 onwards, the RCE affects versions from 6.9.

    “This exploit utilizes a two-part vulnerability chain to achieve unauthenticated SQL injection on a stock WordPress installation with a single HTTP request,” Ben Marr, security engineer at Intruder, explained. “CVE-2026-60137 is the entry point – a route confusion bug in the REST API batch endpoint that bypasses authentication, allowing an attacker to invoke internal handlers without any permission check.”

    “This flaw arises from the improper sanitization of the ‘author__not_in’ parameter within ‘WP_Query’ when untrusted data is passed to it by a plugin or theme. This vulnerability allows crafted input to alter a database query, potentially leading to unauthorized access or manipulation of data.”

    Data from Google-owned Wiz suggests that 60% of organizations using WordPress initially had at least one vulnerable instance at the time these CVEs were published, and 25% were exposing a vulnerable server to the Internet. The figures have since dropped as organizations continue to apply the fixes.

    The cloud security subsidiary has observed the following post-exploitation activities following the abuse of the two flaws –

    • Uploading a malicious plugin
    • Enumerating users and harvesting admin usernames and email addresses
    • Performing local file inclusion (LFI) attacks to target database credentials and authentication keys for exfiltration
    • Accessing the admin panel and successfully authenticating themselves
    • Uploading a bare-bones PHP web shell that facilitates remote code execution

    “We’ve also observed high-volume scanning activity without subsequent post-exploitation, suggesting opportunistic mass-scanning campaigns seeking to identify vulnerable targets alongside legitimate security scanning activity,” Wiz researchers Shahar Dorfman and Gili Tikochinski said. “We have yet to identify lateral movement or data exfiltration, but we continue to monitor and investigate.”

    Cybersecurity

    Also observed as part of the activity is a 150 KB web shell that’s disguised as a legitimate WordPress security plugin called CMSmap. It acts as a “full-featured attack platform” supporting file management, database access, port scanning, batch code injection, and multiple privilege escalation modules, including MySQL UDF exploitation.

    WatchTowr also said attackers have begun to spray the Internet in an indiscriminate fashion following the release of a public exploit, with its honeypots registering “tens of thousands of exploitation attempts.”

    More than 100 backdoor administrator accounts are said to have been created following exploitation, allowing the attackers to deploy fake WordPress plugins to gain code execution or download secondary tools to further compromise the system. In at least one case, a threat actor has been observed repeatedly attempting to install Overlord RAT, a Golang-based remote access trojan.

    Defenders are recommended to inspect their WordPress instances for new administrator accounts, malicious plugins, or other suspicious files, regardless of whether they’ve been patched, to completely root out the threat.

    Exploit Exploitation fuels grows mass Public Scanning Wordpress wp2shell
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous Article‘Too Rare to Care’? A New Center for Rare Diseases Hopes to Change That
    Next Article Enzo Maresca as Man City manager: Can Italian make a success of his return to a club so entrenched in Pep Guardiola’s way? | Football News
    admin
    • Website

    Related Posts

    Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

    July 21, 2026

    New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

    July 21, 2026

    Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs

    July 21, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    1,700 H.I.V. Treatment Sites Closed After Trump Aid Cuts, a Study Finds

    The Xteink X4 Pro could be the tiny e-reader of your dreams

    Why the world trusts China more than America

    Oil Buyers Battered by the Iran War Energy Crisis Race to Build Buffers

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by