logo

Hackers Already Exploiting Newly Patched WordPress Flaws, Researchers Warn

ID: cdebb380-b190-5e71-bc8c-d074496b5541

STIX ID: report--cdebb380-b190-5e71-bc8c-d074496b5541

Feed Name: TechRepublic Security

Threat Score
85/100

Date Published: 2026-07-21

Date Updated: 2026-07-22

Author: Joseph Ofonagoro

...
...

**WP2Shell** — Two chained WordPress Core vulnerabilities (CVE-2026-63030: critical Batch REST API flaw, and CVE-2026-60137: SQL injection) enable pre-auth remote code execution allowing full takeover of vulnerable sites; patches have been released and automatic updates enabled, but security firms report active exploitation and millions of potentially exposed installations, so site owners are urged to apply updates immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.