Critical WordPress Vulnerabilities Exploited Using AI
ID: e0bd8e36-93e7-51da-ab45-88d033ec687c
STIX ID: report--e0bd8e36-93e7-51da-ab45-88d033ec687c
Feed Name: ThreatCluster
Threat Score
Security researchers at Searchlight Cyber disclosed two WordPress Core vulnerabilities (CVE-2026-63030 rated 9.8 and CVE-2026-60137 rated 5.9) impacting WordPress 6.8.x, 6.9.x and 7.0.x that permit unauthenticated remote code execution; an exploit chain called 'WP2Shell' was produced using OpenAI GPT5.6, the flaws were patched in WordPress 7.0.2 on 2026-07-17, and the exploit reportedly worked against a default installation without plugins.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
