logo

Critical WordPress Vulnerabilities Exploited Using AI

ID: e0bd8e36-93e7-51da-ab45-88d033ec687c

STIX ID: report--e0bd8e36-93e7-51da-ab45-88d033ec687c

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-07-20

Date Updated: 2026-07-20

...
...

Security researchers at Searchlight Cyber disclosed two WordPress Core vulnerabilities (CVE-2026-63030 rated 9.8 and CVE-2026-60137 rated 5.9) impacting WordPress 6.8.x, 6.9.x and 7.0.x that permit unauthenticated remote code execution; an exploit chain called 'WP2Shell' was produced using OpenAI GPT5.6, the flaws were patched in WordPress 7.0.2 on 2026-07-17, and the exploit reportedly worked against a default installation without plugins.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.