New WP2Shell Attack Lets Hackers Take Over Vulnerable WordPress Websites

Abeerah Hashim  - Security Expert
Last updated: July 21, 2026
Share
New WP2Shell Attack Lets Hackers Take Over Vulnerable WordPress Websites
  • Researchers have revealed a new attack chain called WP2Shell that lets hackers fully take over some WordPress websites without signing in.
  • The attack joins two WordPress Core flaws and lets attackers create administrator accounts, upload harmful plugins, and run commands on the server.
  • Security experts urge website owners to update WordPress at once because public exploit code is now available and attack attempts have already started.

A newly revealed attack against WordPress Core has raised fresh concerns across the cybersecurity community. Researchers showed that attackers can fully take over vulnerable websites without logging into an account first.

Researchers named the attack chain WP2Shell. It joins two serious WordPress Core vulnerabilities into one attack. Together, they let remote attackers gain complete control of affected websites. The vulnerabilities affect WordPress versions 6.8.0 through 7.0.1. Security experts now urge website owners to install the latest updates as soon as possible.

The attack uses CVE-2026-63030, which affects the WordPress REST API /batch/v1 endpoint. It also uses CVE-2026-60137, a SQL injection flaw linked to the WP_Query::author__not_in parameter.

Each flaw already creates security risks by itself. However, researchers explained that combining both flaws opens a much more dangerous path. The chain can end with complete control of the website and its server.

Researchers explained that attackers do not need valid login details to begin the attack. Instead, they first check if the SQL injection flaw exists on the website. If the target is vulnerable, attackers can increase their access level.

They then create a new administrator account without permission. That new account gives them the ability to upload a harmful plugin. They can also run commands on the server and gain complete control of the website.

Public exploit code raises the risk

The discovery quickly drew attention across the cybersecurity industry. Researchers released technical details explaining how the two vulnerabilities work together. Security companies also warned that public proof-of-concept, also called PoC, code is now available. That code makes the attack much easier for criminals to copy against websites that have not been updated.

The urgency of patching is part of a broader push for better software security. Google has launched a public ledger to verify Android apps and combat supply chain attacks.

According to The Hacker News, WordPress released emergency security updates after receiving responsible reports from security researchers. The company encouraged website owners to install the latest patched versions as quickly as possible. The publication also explained that researchers followed responsible disclosure practices before the technical details became public.

BleepingComputer also warned that public exploit code greatly increases the chance of widespread attacks. The publication explained that attackers now have a much easier way to repeat the full exploit chain against vulnerable WordPress websites. The danger is no longer only theoretical.

According to SecurityWeek, several security companies have already seen attack attempts against vulnerable websites. The report said Patchstack and Hexastrike both observed attempts to exploit the vulnerabilities after details became public.

The report also noted that Cloudflare added protective rules for customers using its web application firewall. Those rules give websites extra protection while administrators install security updates. The growing number of reports shows that attackers are already trying to take advantage of websites that remain unpatched.

Free tool helps website owners check their systems

Security teams are also helping website owners identify exposed systems. ThreatMon IntelHub released a free detection tool that checks whether a website is vulnerable to the WP2Shell attack chain.

The company explained that the tool only checks for exposure. It does not exploit the website or make changes to it. That allows administrators to test their systems safely before attackers find the weakness.

Security experts continue to advise website owners to update WordPress without delay. They also recommend checking for newly created administrator accounts that no one recognizes.

Administrators should inspect installed plugins and remove anything suspicious or unexpected. They should also review recent website changes for signs that attackers may already have gained access.

Experts suggested another temporary safety step while updates are being installed. They recommend blocking outside access to the /wp-json/batch/v1 endpoint and the matching ?rest_route=/batch/v1 route at the network edge.

Researchers explained that this measure can reduce exposure during the update process. However, they stressed that it does not replace installing the official security patches.

Website owners urged to act quickly

WordPress powers a large share of websites around the world. Because of that, flaws that need no login and lead to remote code execution are among the most dangerous security problems. The WP2Shell attack chain combines both of those risks into one exploit. Public exploit code is already available. Security companies have also reported early attack attempts against vulnerable websites.

These developments leave little time for delay. Security experts continue to encourage administrators to install the latest WordPress updates immediately. They also advise monitoring websites for unusual administrator accounts, unexpected plugins, or other signs of unauthorized activity.

The researchers believe that fast action remains the best way to reduce the risk. Websites that receive the latest security updates are far better protected against attackers trying to use the WP2Shell exploit chain.

Share this article

About the Author

Abeerah Hashim

Abeerah Hashim

Security Expert

Abeerah is a passionate technology blogger and cybersecurity enthusiast. She yearns to know everything about the latest technology developments. Specifically, she’s crazy about the three C’s; computing, cybersecurity, and communication. When she is not writing, she’s reading about the tech world.

More from Abeerah Hashim

Comments

No comments.