Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.
July 20, 2026
Attackers have begun widely exploiting two critical vulnerabilities in WordPress that, when chained, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.
The attacks are being fueled by the ready availability of numerous proof-of-concept exploits for the two bugs, identified as CVE-2026-60137 and CVE-2026-63030. Researchers at Searchlight Cyber discovered the flaws using GPT-5.6 Sol Ultra during vulnerability research and have dubbed the exploit chain "WP2Shell."
The flaws affect tens — and potentially even hundreds – of millions of WordPress sites using default install configurations worldwide, giving attackers a vast pool of targets to try and exploit. And given the speed and scale of exploitation, organizations that have not yet patched have a a high likelihood of being compromised already: "Defenders need to inspect their WordPress instances for new administrator accounts, malicious plug-ins, or other suspicious files, regardless of whether they’ve patched," says Jake Knott, principal security researcher at watchTowr.










