21/07/2026
🚨 𝗦𝗘𝗖𝗨𝗥𝗜𝗧𝗬 𝗔𝗗𝗩𝗜𝗦𝗢𝗥𝗬
𝗖𝗿𝗶𝘁𝗶𝗰𝗮𝗹 𝗪𝗼𝗿𝗱𝗣𝗿𝗲𝘀𝘀 𝗥𝗲𝗺𝗼𝘁𝗲 𝗖𝗼𝗱𝗲 𝗘𝘅𝗲𝗰𝘂𝘁𝗶𝗼𝗻 (𝗥𝗖𝗘) 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝘆
A newly disclosed critical vulnerability affecting WordPress Core is currently being actively exploited. Website owners and administrators are strongly advised to verify their WordPress version and apply the latest security updates immediately.
━━━━━━━━━━━━━━━━━━
📌 𝗔𝗳𝗳𝗲𝗰𝘁𝗲𝗱 𝗩𝗲𝗿𝘀𝗶𝗼𝗻𝘀
❌ WordPress 6.9.0 – 6.9.4
➡️ Update to 6.9.5 or later
❌ WordPress 7.0.0 – 7.0.1
➡️ Update to 7.0.2 or later
❌ WordPress 7.1 Beta
➡️ Update to 7.1 Beta 2 or later
━━━━━━━━━━━━━━━━━━
⚠️ 𝗩𝘂𝗹𝗻𝗲𝗿𝗮𝗯𝗶𝗹𝗶𝘁𝘆 𝗢𝘃𝗲𝗿𝘃𝗶𝗲𝘄
The exploit, commonly referred to as "wp2shell", combines two high-severity vulnerabilities:
• CVE-2026-63030 — REST API Route Confusion (CVSS 9.8)
• CVE-2026-60137 — SQL Injection (CVSS 9.1)
Successful exploitation may allow attackers to execute arbitrary code remotely, potentially leading to complete website compromise.
━━━━━━━━━━━━━━━━━━
🛡️ 𝗥𝗲𝗰𝗼𝗺𝗺𝗲𝗻𝗱𝗲𝗱 𝗔𝗰𝘁𝗶𝗼𝗻𝘀
✅ Update WordPress Core immediately to the latest patched version.
✅ If immediate updating is not possible, temporarily disable the WordPress REST API using a trusted security plugin. (Some functionality may be affected.)
✅ If you use a Web Application Firewall (WAF), block:
• /wp-json/batch/v1
• rest_route=/batch/v1
✅ Even if automatic updates are enabled, manually verify that your website has been successfully updated.
━━━━━━━━━━━━━━━━━━
🔒 𝗜𝗺𝗺𝗲𝗱𝗶𝗮𝘁𝗲 𝗔𝗰𝘁𝗶𝗼𝗻 𝗜𝘀 𝗥𝗲𝗾𝘂𝗶𝗿𝗲𝗱
Delaying this update may expose your website to unauthorized access and compromise. We strongly recommend reviewing your WordPress installation and applying the necessary security patches without delay.
Source: Cybernews
— Pro Cloudify Security Team