Millions of WordPress Sites Under Attack as Hackers Exploit Critical Bugs for Full Website Takeover

Millions of WordPress Sites Under Attack as Hackers Exploit Critical Bugs for Full Website Takeover


Millions of websites running vulnerable versions of WordPress are facing an escalating cyberattack campaign as hackers exploit two critical security flaws that can allow complete control of affected sites.

Security researchers warn that attackers are already using publicly available exploit tools to break into websites, steal data and install malicious backdoors.

The vulnerabilities, tracked as CVE-2026-60137 and CVE-2026-63030, affect WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. When combined, the two flaws create an attack chain dubbed “WP2Shell,” enabling attackers with no login credentials to remotely execute malicious code on vulnerable systems.

WordPress released a security update on July 17 and urged administrators to update immediately. Due to the severity of the flaws, the WordPress.org team enabled forced updates through its automatic update system wherever possible.

“Due to the severity, the WordPress.org team have enabled forced updates via the auto-update system for sites running affected versions,” WordPress said.

Critical Bugs Open Door to Remote Takeover of Websites

As reported, cybersecurity firms including Patchstack, Hexastrike and WatchTowr have confirmed that attackers are actively exploiting the vulnerabilities in real-world attacks. Researchers say the threat is particularly dangerous because the flaws can be chained together to bypass authentication and gain complete control over a website.

The first vulnerability, CVE-2026-60137, is an SQL injection flaw that allows attackers to manipulate database queries and access restricted information. On its own, the flaw requires authentication, but when combined with CVE-2026-63030, a logic flaw in WordPress’ Batch REST API, attackers can exploit it without logging in.

The result is a powerful attack method that gives cybercriminals remote code execution capabilities, allowing them to run commands, create administrator accounts and install malicious software.

“SQLi on its own gets you into the WordPress database. RCE gets you the whole server,” Patrick Munch, chief security officer at Mondoo, told Dark Reading, adding that “Put them and a bug that ‘only’ leaks data, and you end up with a web shell on the host”.

Cybersecurity experts estimate the number of vulnerable websites could reach tens of millions. Daniel Card, a cybersecurity consultant who analyzed thousands of WordPress sites, estimated that fewer than 15% of websites in his sample were still vulnerable.

If applied across the global WordPress ecosystem, that could represent around 90 million exposed sites.

WordPress.org

Hackers Launch Rapid Attacks Using Public Exploits

The speed of exploitation has raised concerns among security professionals. Researchers say attackers began scanning and targeting vulnerable WordPress installations almost immediately after details of the flaws became public.

WatchTowr researchers monitoring attacks through their honeypot network observed thousands of exploitation attempts. The company recorded more than 100 backdoor administrator accounts created by threat actors using different versions of publicly available attack tools.

“Once a backdoor administrator account was created, attackers deployed fake WordPress plug-ins to gain Remote Code Execution, exfiltrate credentials or secrets, or download additional tooling to further compromise the system,” Jake Knott, principal security researcher at WatchTowr, said.

Researchers also observed attackers attempting to deploy additional malware, including remote access tools designed to maintain long-term control over compromised systems.

The availability of proof-of-concept exploits has accelerated the threat. VulnCheck reported that more than two dozen unique exploit demonstrations targeting WP2Shell had already appeared shortly after disclosure.

AI’s Growing Role in Finding and Weaponizing Flaws

The discovery of the vulnerabilities also highlighted the increasing role of artificial intelligence in cybersecurity, both for defenders and attackers.

Searchlight Cyber researcher Adam Kues discovered the flaws during vulnerability research using GPT-5.6 Sol Ultra and said AI dramatically reduced the time required to develop the exploit chain.

“I can say with complete confidence that no security researcher could have found and completed this exploit chain in 10 hours without AI,” Kues wrote.

Security experts warn that AI could allow attackers to reproduce newly disclosed vulnerabilities faster than ever before. WatchTowr’s Knott said that once technical details became public, recreating exploits with advanced AI tools was only a matter of time.

“Once the vulnerabilities were publicly disclosed, reproducing them with the help of frontier AI models was only a matter of time and tokens,” Knott said.

While some WordPress hosting providers had already protected their customers before the patch was released, experts are urging all administrators to check their systems immediately.

Security teams should look for unknown administrator accounts, suspicious plugins and unusual files, even on sites that have already installed the update.

With hundreds of millions of websites powered by WordPress worldwide, researchers warn that delayed patching could leave organizations vulnerable to automated attacks sweeping the internet for easy targets.



Source link

Posted in

Liam Redmond

As an editor at Forbes Europe, I specialize in exploring business innovations and entrepreneurial success stories. My passion lies in delivering impactful content that resonates with readers and sparks meaningful conversations.

Leave a Comment