Are More Than 500 Million WordPress Websites at Risk? A New Critical “wp2shell” Vulnerability Allows Complete Remote Server Compromise!

Imported from official source

Announcement

A critical new vulnerability, dubbed “wp2shell,” has been discovered in WordPress, one of the world’s most widely used content management systems (CMS). If successfully exploited, this flaw allows attackers to execute arbitrary code remotely (Remote Code Execution – RCE) on the server and gain complete control over a website without authentication and without relying on any additional plugins.

According to security experts, this vulnerability could pose a serious threat to more than 500 million WordPress websites. As a result, the WordPress development team has released emergency security updates and is urging all users to update their systems immediately.

How does the “wp2shell” vulnerability work?

The vulnerability stems from a logical flaw in the REST API Batch Route mechanism within WordPress Core. This flaw creates a Batch Route Confusion issue during REST API request processing, enabling an attacker to perform an SQL Injection attack. The attack chain can then be escalated to achieve Remote Code Execution (RCE).

The most alarming aspect is that the attack does not require:

  • any non-default WordPress configuration.
  • This means that virtually any vulnerable internet-facing WordPress installation could become a target for automated cyberattacks.

    The vulnerability affects the following WordPress Core versions:

    Additionally, the vulnerabilities have been assigned the following identifiers:

  • CVE-2026-60137 — SQL Injection vulnerability;
  • CVE-2026-63030 — “wp2shell” Remote Code Execution vulnerability.
  • It is important to note that the WordPress 6.8 branch is only affected by the SQL Injection vulnerability and is not vulnerable to the RCE attack chain. This issue has been fixed in WordPress 6.8.6.

    Remote Code Execution (RCE) vulnerabilities are considered among the most critical security flaws in cybersecurity.

    An attacker who successfully exploits this vulnerability could:

  • use the compromised server as a staging point for ransomware attacks.
  • This is an extract. The publication continues at the source.

    Read the original at the source: https://uzcert.uz/en/are-more-than-500-million-wordpress-websites-at-risk-a-new-critical-wp2shell-vulnerability-allows-complete-remote-server-compromise-2/

    Officially imported this from UZCERT’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

    Provenance

    Organization
    UZCERT — imported from official source
    Official source
    https://uzcert.uz/en/feed/ RSS
    Imported
    October 03, 2026 20:40
    Versions
    1 recorded
    Identity
    https://uzcert.uz/?p=39229

    Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.