Ethical Hacking News
A new vulnerability has left millions of websites vulnerable to exploitation, allowing attackers to gain unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. Learn more about the WordPress wp2shell vulnerability and how to mitigate its effects.
The newly discovered "wp2shell" vulnerability in WordPress allows attackers to gain unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The vulnerability was discovered by Searchlight Cyber using OpenAI GPT 5.6 Sol and affects default WordPress installations in any version released since December 2025. The wp2shell vulnerability has significant implications for web security, with 60% of organizations initially having at least one vulnerable instance, according to Wiz data. Attackers have begun exploiting the vulnerability through various means, including uploading malicious plugins, enumerating users, and performing local file inclusion attacks. The vulnerability is also being used in mass-scanning campaigns, with high-volume scanning activity observed without subsequent post-exploitation. Attackers are using the wp2shell vulnerability to create backdoor administrator accounts and deploy fake plugins to gain code execution or download secondary tools. Defenders are urged to inspect their WordPress instances for suspicious activity, use tools and techniques such as scanning and monitoring logs, and perform regular security audits.
The world of web security is under siege as a newly discovered vulnerability, dubbed "wp2shell," has left millions of websites vulnerable to exploitation. The attack, which leverages two critical vulnerabilities in WordPress, allows attackers to gain unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. In this article, we will delve into the details of the wp2shell vulnerability, its implications for web security, and the steps that can be taken to mitigate its effects.
The discovery of the wp2shell vulnerability is attributed to Searchlight Cyber, a cybersecurity firm that utilizes OpenAI GPT 5.6 Sol to discover vulnerabilities in software. According to Searchlight Cyber, the exploit chain discovered by their team allows unauthenticated attackers to gain remote code execution on default WordPress installations in any WordPress version released since December 2025. This is a particularly concerning development, as it means that even sites using the latest versions of WordPress can be compromised.
The wp2shell vulnerability has far-reaching implications for web security. According to Cloudflare, CVE-2026-63030 enables unauthenticated remote code execution (RCE) only when persistent object cache is not in use. This means that websites with an enabled cache are less likely to be vulnerable, but those without it are at risk. Furthermore, the SQL injection vulnerability (CVE-2026-60137) is present from version 6.8 onwards, making older versions of WordPress also susceptible.
The attack mechanism involves a two-part vulnerability chain. The first vulnerability, CVE-2026-63030, enables attackers to bypass authentication and invoke internal handlers without any permission check. The second vulnerability, CVE-2026-60137, arises from the improper sanitization of the "author__not_in" parameter within "WP_Query." This allows crafted input to alter a database query, potentially leading to unauthorized access or manipulation of data.
The wp2shell vulnerability has already had significant real-world implications. According to data from Google-owned Wiz, 60% of organizations using WordPress initially had at least one vulnerable instance at the time these CVEs were published, and 25% were exposing a vulnerable server to the Internet. The figures have since dropped as organizations continue to apply the fixes.
However, the attack is not limited to these initial vulnerabilities. According to Cloudflare, attackers have begun to exploit the wp2shell vulnerability in various ways, including uploading malicious plugins, enumerating users and harvesting admin usernames and email addresses, performing local file inclusion (LFI) attacks to target database credentials and authentication keys for exfiltration, accessing the admin panel and successfully authenticating themselves, uploading a bare-bones PHP web shell that facilitates remote code execution, and more.
The wp2shell vulnerability is also being used in mass-scanning campaigns. According to Wiz researchers Shahar Dorfman and Gili Tikochinski, high-volume scanning activity has been observed without subsequent post-exploitation, suggesting opportunistic mass-scanning campaigns seeking to identify vulnerable targets alongside legitimate security scanning activity.
Furthermore, attackers have begun to use the wp2shell vulnerability in more sophisticated attacks. According to WatchTowr, attackers have created over 100 backdoor administrator accounts following exploitation, allowing them to deploy fake WordPress plugins to gain code execution or download secondary tools to further compromise the system. In at least one case, a threat actor has been observed repeatedly attempting to install Overlord RAT, a Golang-based remote access trojan.
In light of these findings, defenders are urged to inspect their WordPress instances for new administrator accounts, malicious plugins, or other suspicious files, regardless of whether they've been patched, to completely root out the threat. This includes using tools and techniques such as scanning for suspicious activity, monitoring logs for potential anomalies, and performing regular security audits.
In conclusion, the wp2shell vulnerability represents a significant threat to web security. Its implications are far-reaching, and its impact will likely be felt across the internet for some time to come. As we continue to navigate this complex and rapidly evolving landscape of cybersecurity threats, it is essential that defenders remain vigilant and proactive in their efforts to protect themselves and their organizations from these types of attacks.
A new vulnerability has left millions of websites vulnerable to exploitation, allowing attackers to gain unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. Learn more about the WordPress wp2shell vulnerability and how to mitigate its effects.
Related Information:
https://www.ethicalhackingnews.com/articles/Unveiling-the-Extent-of-the-WordPress-wp2shell-Vulnerability-A-Looming-Threat-to-Web-Security-ehn.shtml
https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html
Published: Tue Jul 21 04:21:25 2026 by llama3.2 3B Q4_K_M