THE article discusses recently released public exploits targeting critical vulnerabilities in WordPress, specifically CVE-2026-63030 and CVE-2026-60137. These flaws allow remote code execution without authentication on default WordPress installations (versions 6.9.x and 7.0.x). Cybersecurity researchers from Searchlight Cyber discovered these issues, emphasizing the urgency of updating to WordPress 7.0.2 or 6.9.5 to mitigate risks. Temporary measures include blocking access to specific REST API endpoints. Over 500 million websites utilize WordPress, making immediate patching essential to prevent exploitation.
Public PoC exploits hit critical WordPress CVEs, urging patches
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
WordPress wp2shell flaw lets attackers run code before login
elastic.co
-
WordPress wp2shell exploit fuels surge in site scans and attacks
thehackernews.com
-
Critical WordPress Bug Lets Attackers Run Code Remotely
securityonline.info
-
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
darkreading.com
-
WordPress core flaw CVE-2026-63030 lets attackers execute code
isc.sans.edu
-
AI crafted WordPress exploit chain triggers urgent CVE patches
infosecurity-magazine.com
-
WordPress flaws CVE-2026-60137 and CVE-2026-63030 allow RCE
securityweek.com
-
Public PoC exploits hit critical WordPress CVEs, urging patches
securityaffairs.com
-
WordPress SQLi bug allows remote code execution, update now
securityonline.info
-
WordPress REST API flaw lets attackers run code remotely
rapid7.com