Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Microsoft shares manual fix for WSUS sync delays and timeouts

    July 21, 2026

    Finding the Routers Energetic Bear Is Looking For | Blog

    July 21, 2026

    SonicWall SMA1000 flaws exploited as zero-days to push custom malware

    July 20, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»WP2Shell Vulnerabilities: CVE-2026-60137 and CVE-2026-63030 | Blog
    News

    WP2Shell Vulnerabilities: CVE-2026-60137 and CVE-2026-63030 | Blog

    adminBy adminJuly 20, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email



    • A new version of WordPress core was released on Friday, July 17 with fixes for two high-profile vulnerabilities that, when exploited together, allow for remote code execution on standard WordPress installations.
    • The vulnerabilities have been assigned CVE-2026-60137 (critical SQL injection) and CVE-2026-63030 (high-severity REST API batch endpoint route confusion).
    • Not all versions of WordPress are vulnerable, but the CMS’s global popularity means any new vulnerability has a large built-in target population. While there was no exploitation at time of disclosure, early reports of in-the-wild activity have since begun to emerge. VulnCheck Canaries have observed active exploitation as of July 20.

    On Friday, July 17, 2026 the WordPress team released version 7.0.2 of the popular CMS to address two vulnerabilities — one critical-severity and one high-severity — that when exploited together allow for remote code execution in out-of-the-box WordPress installations (no plugins needed). Public details on the vulnerabilities themselves were lacking sparse early on, ostensibly to prevent exploitation. Since fixes were released, dozens of exploit implementations have been published, with multiple exploit variants now circulating ont he internet. Searchlight Cyber, whose research team is credited for discovery of CVE-2026-63030, nicknamed the vulnerability “WP2Shell” in a companion advisory.

    While there wasn’t any reported exploitation in the wild at time of disclosure, security firm PatchStack began reporting exploitation of both CVEs as of shortly before 7 PM ET on Friday, July 17, though it’s unclear what exactly is being observed in the wild. VulnCheck’s Canary Intelligence network has also observed in-the-wild exploitation against real production systems. Popular ASM engines, including Censys and Shodan, find tens of millions of WordPress installations on the public internet.

    As of Sunday, July 19, VulnCheck has verified more than two dozen unique PoCs targeting WP2Shell.

    VulnCheck’s research team began investigating the WordPress patches upon their release. Our exploit development team’s initial assessment was that based on the advisory and public fix commits, CVE-2026-60137 (SQLi) is reachable on its own only by an authenticated user. When chained with CVE-2026-63030, however, the secondary vulnerability bypasses the blocklist that restricts the CVE-2026-60137 SQL injection to authenticated users only, and therefore makes the entire chain unauthenticated.

    In our team’s early research, RCE was reliant upon CVE-2026-63030 (batch-route confusion that functions as an “auth bypass”, for lack of a better term) to unblock the authed SQL injection, after which it was possible to dump the target database, steal and crack an admin user’s password, and log in as the admin — utlimately allowing an adversary to log in as an admin and upload a webshell or conduct any other manner of nefarious activity. Later research demonstrated that RCE does not require admin password hash cracking (which in effect would have made the exploit an information disclosure rather than a native code execution chain). Instead, the batch-route confusion issue allows an unauthenticated adversary to access authenticated endpoints (i.e., making CVE-2026-60137 unauthenticated) and create a new, malicious administrative user — which can then conduct typical post-exploitation activity.

    Two different exploit variants — an information disclosure variant and the full RCE variant — are available to VulnCheck Initial Access Intelligence customers, along with Suricata/Snort/YARA rules, PCAPs, a version scanner, and a target Docker container.

    CVE Vulnerability Affects Fixed In
    CVE-2026-60137 Facilitated SQL injection in author__not_in parameter of WP_Query 6.8.0 – 6.8.5, 6.9.0 – 6.9.4, 7.0.0 – 7.0.1 6.8.6, 6.9.5, 7.0.2
    CVE-2026-63030 REST API batch endpoint route confusion and SQLi 6.9.0 – 6.9.4, 7.0.0 – 7.0.1 6.9.5, 7.0.2

    The WordPress team’s advisory notes that affected versions vary across each specific vulnerability, which is also captured in the table above. From the WordPress advisory:

    • WordPress 6.9 is affected by both vulnerabilities. Version 6.9.5 has been released containing fixes for both.
    • WordPress 6.8 is only affected by the first vulnerability. Version 6.8.6 has been released containing a fix.
    • The beta release of WordPress 7.1 is affected by both vulnerabilities. Version 7.1 beta2 has been released containing fixes for both.
    • Versions of WordPress prior to 6.8 are not affected.

    Affected users should update to a fixed version of WordPress as soon as possible, given the availability of various public exploits and the likelihood of large-scale exploitation.

    VulnCheck empowers organizations to transcend the challenges of vulnerability prioritization. Our suite of solutions provides product managers, PSIRT teams, and threat hunters with the tools required for accelerated, high-precision operations and infinite efficiency.

    Recognizing the industry-wide necessity for superior data velocity and accuracy, we deliver high-fidelity insights to the market. We remain committed to surfacing critical intelligence on vulnerability exploitation and emerging trends, leveraging our unique dataset to support the practitioner community.

    For more research like this, see Finding the Routers Energetic Bear Is Looking For, Monsta FTP: An SSRF Blocklist That Forgot IPv6 Exists, and Copy Fail and Its Descendants: A Real Human’s Guide to Kernel Page-Cache LPEs.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleNew Orleans Cops Published Policy Document Allowing Weaponized Drones
    Next Article Estée Lauder discloses data breach via Oracle E-Business flaw
    admin
    • Website

    Related Posts

    News

    Microsoft shares manual fix for WSUS sync delays and timeouts

    July 21, 2026
    News

    Finding the Routers Energetic Bear Is Looking For | Blog

    July 21, 2026
    News

    SonicWall SMA1000 flaws exploited as zero-days to push custom malware

    July 20, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202635 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202634 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    IP Address Investigations and Local OSINT

    March 20, 202635 Views

    The Canadian Password Playbook: Navigating Compliance and Building Strong Passwords

    March 25, 202634 Views
    Our Picks

    Microsoft shares manual fix for WSUS sync delays and timeouts

    July 21, 2026

    Finding the Routers Energetic Bear Is Looking For | Blog

    July 21, 2026

    SonicWall SMA1000 flaws exploited as zero-days to push custom malware

    July 20, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.