The actively exploited “wp2shell” exploit chain combines WordPress vulnerabilities for unauthenticated remote code execution — upgrade to version 7.0.2 is required.
A validation flaw in WordPress’s REST Batch API enables pre-authentication remote code execution with full control over website, database, and hosting environment.
An indexing flaw in the REST batch endpoint allows unauthenticated attackers to gain complete control over WordPress installations, but requires immediate patching to version 6.9.5 or 7.0.2.
CVE-2026-60137 and CVE-2026-63030 enable unauthenticated remote code execution on WordPress 6.9–7.0.1 without prerequisites when both vulnerabilities are combined.
Cybercriminals are conducting a global campaign exploiting vulnerabilities in WordPress, Joomla and other CMS systems to deploy webshells and gain administrator access.
Operation Endgame has cleaned 14,971 compromised WordPress websites from the SocGholish malware network, which is attributed to the Russian cybercrime group Evil Corp.
Attackers compromised the update mechanisms of three WordPress plugins and distributed malware to over one million users through a supply-chain vulnerability.
Three popular WordPress plugins were abused to create attacker-controlled admin accounts and install backdoor plugins, deliberately targeting administrators as the attack vector.