Two newly patched WordPress vulnerabilities are being exploited in the wild, with attacks beginning shortly after they came to light.
The vulnerabilities have been dubbed WP2Shell and they are officially tracked as CVE-2026-60137 and CVE-2026-63030.
According to Searchlight Cyber, whose researchers discovered the flaws, WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected.
“The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins,” the security firm warned.
WordPress announced patches on Friday with the release of versions 6.9.5 and 7.0.2.








