WP2Shell Vulnerabilities Exploited in the Wild

On July 17, Coalition notified impacted policyholders about two vulnerabilities in WordPress Core, CVE-2026-63030 and CVE-2026-60137, which attackers can chain together to achieve unauthenticated remote code execution (RCE), resulting in complete compromise.
One of these vulnerabilities, which threat actors can exploit without plugins or special credentials, received a critical-severity CVSS score of 9.8. Proof-of-concept (PoC) exploits are circulating and our Coalition honeypots have captured active exploitation attempts in the wild.
Due to the high risk, WordPress enabled forced updates via the auto-update system for sites running affected versions. Coalition urges policyholders to verify that they have applied the patch. If automated background updates are not enabled, businesses should prioritize manually upgrading immediately.
What’s happening?
On July 17, security researchers at Searchlight Cyber disclosed both vulnerabilities, which can be combined into an unauthenticated RCE chain, impacting WordPress Core:
CVE-2026-63030: REST API batch-route confusion vulnerability
CVE-2026-60137: Does not properly sanitize the ‘author__not_in’ parameter of ‘WP_Query,’ which could allow SQL injection when a plugin or theme passes untrusted input to the parameter
The complete RCE chain affects WordPress 6.9.0 through 6.9.4 and WordPress 7.0.0 through 7.0.1.
The majority of documented WordPress vulnerabilities originate in plugins designed by third-party developers. These vulnerabilities, while common, are restricted to sites running the impacted plugin.
The WP2Shell vulnerabilities impact WordPress Core, which means that all sites running an impacted version (WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1) may be vulnerable. For context, WordPress is one of the most widely deployed content management systems, powering approximately 43% of all websites.
On July 20, Coalition observed active exploitation of the WP2Shell vulnerabilities on our honeypots — decoys that appear as vulnerable machines to attackers — reinforcing the need for policyholders to patch urgently.

How should businesses address this?
To mitigate these critical vulnerabilities, businesses should update their WordPress systems to a patched version:
WordPress 6.9.0 users should update to 6.9.5 or newer
WordPress 7.0.0 users should update to 7.0.2 or newer
Although Web Application Firewalls may provide some protection, patching is the only complete fix. To help ensure immediate fixes for future security patches, businesses should enable automatic background updates from WordPress. In addition, businesses that suspect or have evidence of unauthorized access before patching should ensure they follow appropriate Digital Forensics and Incident Response (DFIR) steps, including searching logs for evidence of compromise, newly created admin users, or newly installed plugins.
Who’s at risk?
Searchlight Cyber’s advisory states that WP2Shell has “no preconditions and can be exploited by an anonymous user.” Without any preconditions, attackers have a relatively clear path to exploitation. Given that WordPress runs an estimated 500 million sites, the scale is enormous.
All policyholders using WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 should verify that the forced auto-updates were applied to every instance running or should manually update to a fixed release now.
How Coalition is responding
Coalition notified all impacted policyholders on July 17 — 24 hours before active exploitation began. Coalition policyholders can log in to Coalition Control® for the latest updates.
Businesses can also check if their instance is vulnerable through Searchlight Cyber’s public WP2Shell checker.
For assistance with mitigation, contact Coalition’s Security Support Center at securitysupport@coalitioninc.com.
SPOT & STOP CYBER THREATS
Coalition Control
Take control of your cyber risk >






