Ethical Hacking News
A critical vulnerability was discovered in WordPress, allowing attackers to gain pre-authentication remote code execution (RCE) access to vulnerable systems. Experts warn that organizations waiting until Monday to patch are likely already compromised. The impact of this vulnerability has been widespread, with numerous backdoor accounts created by different threat actors using variations of public tooling observed.
The recent WordPress vulnerability (CVE-2026-63030 and CVE-2026-60137) allows attackers to gain unauthorized access to vulnerable systems. A critical REST API batch-route confusion bug (CVE-2026-63030) can be exploited by an anonymous user, while a moderate-severity SQL injection issue (CVE-2026-60137) allows for pre-authentication remote code execution (RCE). Attackers quickly exploited the vulnerabilities, creating over 100 backdoor accounts using public exploit code. The impact of this vulnerability has been widespread, with organizations of all sizes and verticals affected. Experts warn that organizations that waited to patch may already be compromised, and defenders need to inspect their systems for suspicious activity.
The recent vulnerability in WordPress, a content management system used by millions of websites worldwide, has raised concerns among security experts and users alike. The vulnerabilities, known as CVE-2026-63030 and CVE-2026-60137, were discovered earlier this month, and attackers quickly began exploiting them to gain unauthorized access to vulnerable systems.
The first vulnerability, CVE-2026-63030, is a critical REST API batch-route confusion bug that can be exploited by an anonymous user in a stock install of WordPress with no plugins. When chained together with the second vulnerability, CVE-2026-60137, which is a moderate-severity SQL injection issue, attackers can gain pre-authentication remote code execution (RCE) access to vulnerable systems.
According to security researcher Jake Knott, who worked at watchTowr, a principal security researcher, once the vulnerabilities were publicly disclosed, reproducing them with the help of frontier AI models was only a matter of time and tokens. WatchTowr was able to trivially reproduce CVE-2026-63030 within minutes of disclosure, and the second CVE-2026-60137 with some additional effort.
The attackers began spraying the internet indiscriminately, hitting anything reachable and trying to get lucky. They used public exploit code to exfiltrate hashed credentials, followed by remote code execution once additional details were made public. Over 100 backdoor accounts created by different threat actors using variations of public tooling were observed by watchTowr.
Security firm PatchStack reported exploitation of both CVEs as of Friday night but didn't provide details about the attacks. In a subsequent advisory, Searchlight Cyber researcher Adam Kues dubbed the bug wp2shell and released a free wp2shell checker to determine if your instance is vulnerable.
The impact of this vulnerability has been widespread, with organizations of every size and vertical being affected. John Blackbourn, one of the WordPress core developers, recommended that affected users update their sites immediately due to the severity of the flaws. The WordPress security team also enabled forced updates via the auto-update system for sites running affected versions.
Because of the severe impact this vulnerability has had, experts warn that organizations that waited until Monday to patch are likely already compromised. To inspect their systems, defenders need to check for new administrator accounts, malicious plugins, or other suspicious files, regardless of whether they’ve patched.
Cybersecurity is a vital sector in today’s world, and one can never be overly cautious when it comes to data security. With AI becoming more prevalent, the rise of sophisticated cyber threats has become inevitable. This recent WordPress vulnerability serves as a stark reminder that data security must remain top priority for organizations worldwide.
Related Information:
https://www.ethicalhackingnews.com/articles/Attacking-WordPress-A-Critical-Vulnerability-and-the-Rise-of-AI-Assisted-Cybercrime-ehn.shtml
https://www.theregister.com/security/2026/07/20/attackers-pummel-critical-wordpress-vuln-to-create-all-sorts-of-mischief/5275265
https://nvd.nist.gov/vuln/detail/CVE-2026-63030
https://www.cvedetails.com/cve/CVE-2026-63030/
https://nvd.nist.gov/vuln/detail/CVE-2026-60137
https://www.cvedetails.com/cve/CVE-2026-60137/
Published: Mon Jul 20 17:06:44 2026 by llama3.2 3B Q4_K_M