It’s Official: Coalition & Allianz Commercial Finalize Strategic Global Cyber Insurance Partnership
Cyber Incident? Get Help

WP2Shell Vulnerabilities Exploited in the Wild

wp2shell

On July 17, Coalition notified impacted policyholders about two vulnerabilities in WordPress Core, CVE-2026-63030 and CVE-2026-60137, which attackers can chain together to achieve unauthenticated remote code execution (RCE), resulting in complete compromise.

One of these vulnerabilities, which threat actors can exploit without plugins or special credentials, received a critical-severity CVSS score of 9.8. Proof-of-concept (PoC) exploits are circulating and our Coalition honeypots have captured active exploitation attempts in the wild. 

Due to the high risk, WordPress enabled forced updates via the auto-update system for sites running affected versions. Coalition urges policyholders to verify that they have applied the patch. If automated background updates are not enabled, businesses should prioritize manually upgrading immediately.

What’s happening?

On July 17, security researchers at Searchlight Cyber disclosed both vulnerabilities, which can be combined into an unauthenticated RCE chain, impacting WordPress Core:

  • CVE-2026-63030: REST API batch-route confusion vulnerability 

  • CVE-2026-60137: Does not properly sanitize the ‘author__not_in’ parameter of ‘WP_Query,’ which could allow SQL injection when a plugin or theme passes untrusted input to the parameter

The complete RCE chain affects WordPress 6.9.0 through 6.9.4 and WordPress 7.0.0 through 7.0.1. 

The majority of documented WordPress vulnerabilities originate in plugins designed by third-party developers. These vulnerabilities, while common, are restricted to sites running the impacted plugin. 

The WP2Shell vulnerabilities impact WordPress Core, which means that all sites running an impacted version (WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1) may be vulnerable. For context, WordPress is one of the most widely deployed content management systems, powering approximately 43% of all websites

On July 20, Coalition observed active exploitation of the WP2Shell vulnerabilities on our honeypots — decoys that appear as vulnerable machines to attackers — reinforcing the need for policyholders to patch urgently.

Honeypot

How should businesses address this?

To mitigate these critical vulnerabilities, businesses should update their WordPress systems to a patched version:

  • WordPress 6.9.0 users should update to 6.9.5 or newer

  • WordPress 7.0.0 users should update to 7.0.2 or newer

Although Web Application Firewalls may provide some protection, patching is the only complete fix. To help ensure immediate fixes for future security patches, businesses should enable automatic background updates from WordPress. In addition, businesses that suspect or have evidence of unauthorized access before patching should ensure they follow appropriate Digital Forensics and Incident Response (DFIR) steps, including searching logs for evidence of compromise, newly created admin users, or newly installed plugins.

Who’s at risk?

Searchlight Cyber’s advisory states that WP2Shell has “no preconditions and can be exploited by an anonymous user.” Without any preconditions, attackers have a relatively clear path to exploitation. Given that WordPress runs an estimated 500 million sites, the scale is enormous.

All policyholders using WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 should verify that the forced auto-updates were applied to every instance running or should manually update to a fixed release now.

How Coalition is responding

Coalition notified all impacted policyholders on July 17 — 24 hours before active exploitation began.  Coalition policyholders can log in to Coalition Control® for the latest updates. 

Businesses can also check if their instance is vulnerable through Searchlight Cyber’s public WP2Shell checker.

For assistance with mitigation, contact Coalition’s Security Support Center at securitysupport@coalitioninc.com.


SPOT & STOP CYBER THREATS 

Coalition Control

Take control of your cyber risk >


This blog post is designed to provide general information on the topic presented and is not intended to construe or render legal or other professional services of any kind. If legal or other professional advice is required, the services of a professional should be sought. The views and opinions expressed as part of this blog post do not necessarily state or reflect those of Coalition. Neither Coalition nor any of its employees make any warranty of any kind, express or implied, or assume any legal liability or responsibility for the accuracy, completeness, or usefulness of any information, product, or process disclosed. Any action you take upon the information contained herein is strictly at your own risk. Coalition and its affiliates will not be liable for any losses and damages in connection with your use or reliance upon the information. The blog post may include links to other third-party websites. These links are provided as a convenience only. Coalition does not endorse, have control over, nor assumes responsibility or liability for the content, privacy policy, or practices of any such third-party websites.
Copyright © 2026. All rights reserved. Coalition and the Coalition logo are trademarks of Coalition, Inc.

Related blog posts

See all articles
Security

Blog

How Login Security Helps Businesses Combat Identity-Based Threats

Business email compromise is the leading driver of cyber claims. Login Security monitors suspicious login activity and kicks out attackers.
Kartik MurthyJuly 21, 2026
Security

Blog

How We Reduce Alert Noise for MSPs by 99.99%

With traditional MDR, your team is still overwhelmed by false positives. Automated detection and response bridges the gap left by human-led protection.
Jake ReynoldsJune 02, 2026
Security

Blog

Why MDR is Failing: Is Your Detection Tool a High-Priced Alarm?

Defenders are being confronted with an unprecedented speed crisis. Traditional human-led managed detection and response timelines no longer work.
Dara BernsteinMay 26, 2026