{"id":6453,"date":"2026-07-18T22:52:21","date_gmt":"2026-07-18T22:52:21","guid":{"rendered":"https:\/\/lockitsoft.com\/?p=6453"},"modified":"2026-07-18T22:52:21","modified_gmt":"2026-07-18T22:52:21","slug":"wordpress-core-vulnerability-wp2shell-allows-anonymous-code-execution-via-chained-exploits","status":"publish","type":"post","link":"https:\/\/lockitsoft.com\/?p=6453","title":{"rendered":"WordPress Core Vulnerability &#8216;wp2shell&#8217; Allows Anonymous Code Execution via Chained Exploits"},"content":{"rendered":"<p><strong>July 18, 2026<\/strong> \u2013 A critical security vulnerability within the core of WordPress, dubbed &quot;wp2shell,&quot; has been fully detailed, revealing a two-part exploit chain that allows anonymous attackers to execute arbitrary code on vulnerable websites. Initially flagged by researchers, the vulnerabilities have now been assigned CVE identifiers, the complete exploitation mechanism has been published, and a working proof-of-concept is publicly available, escalating the urgency for website administrators to update their systems.<\/p>\n<p>The exploit leverages two distinct flaws: CVE-2026-63030, a confusion in the REST API&#8217;s batch routing, and CVE-2026-60137, a SQL injection vulnerability within WordPress core itself. When chained together, these vulnerabilities enable an attacker to bypass authentication entirely and achieve code execution on a target WordPress site. This means even a bare installation of WordPress, without any third-party plugins, can be compromised. All sites running versions 6.9 and 7.0 were susceptible until WordPress released critical patches in versions 6.9.5 and 7.0.2, which were deployed via its auto-update system, including a forced update mechanism.<\/p>\n<p>The timeline of this disclosure highlights a race between patching and exploitation. Adam Kues from Assetnote, the attack surface management division of Searchlight Cyber, discovered the batch-route confusion and reported it through WordPress&#8217;s official HackerOne program. His findings, published under the moniker &quot;wp2shell,&quot; underscored the severity of the attack, stating it possesses &quot;no preconditions and can be exploited by an anonymous user.&quot; The SQL injection component was reported independently by a trio of researchers: TF1T, dtro, and haongo.<\/p>\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_82_2 counter-hierarchy ez-toc-counter ez-toc-grey ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/lockitsoft.com\/?p=6453\/#The_Anatomy_of_the_wp2shell_Exploit\" >The Anatomy of the wp2shell Exploit<\/a><ul class='ez-toc-list-level-4' ><li class='ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/lockitsoft.com\/?p=6453\/#CVE-2026-63030_REST_API_Batch-Route_Confusion\" >CVE-2026-63030: REST API Batch-Route Confusion<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/lockitsoft.com\/?p=6453\/#CVE-2026-60137_SQL_Injection_in_WordPress_Core\" >CVE-2026-60137: SQL Injection in WordPress Core<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-4'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/lockitsoft.com\/?p=6453\/#The_Chained_Exploitation\" >The Chained Exploitation<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/lockitsoft.com\/?p=6453\/#Scope_of_Vulnerability_and_Patching_Efforts\" >Scope of Vulnerability and Patching Efforts<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/lockitsoft.com\/?p=6453\/#Background_and_Discovery\" >Background and Discovery<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/lockitsoft.com\/?p=6453\/#Broader_Implications_and_Analysis\" >Broader Implications and Analysis<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/lockitsoft.com\/?p=6453\/#A_Persistent_Object_Cache_Condition\" >A Persistent Object Cache Condition<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/lockitsoft.com\/?p=6453\/#Official_Responses_and_Industry_Reactions\" >Official Responses and Industry Reactions<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/lockitsoft.com\/?p=6453\/#Mitigations_for_Unpatched_Systems\" >Mitigations for Unpatched Systems<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/lockitsoft.com\/?p=6453\/#The_Race_Against_Time\" >The Race Against Time<\/a><\/li><\/ul><\/nav><\/div>\n<h3><span class=\"ez-toc-section\" id=\"The_Anatomy_of_the_wp2shell_Exploit\"><\/span>The Anatomy of the wp2shell Exploit<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The wp2shell exploit is a sophisticated chaining of two separate vulnerabilities, each with its own scope and impact.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"CVE-2026-63030_REST_API_Batch-Route_Confusion\"><\/span>CVE-2026-63030: REST API Batch-Route Confusion<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>This vulnerability, discovered by Adam Kues of Assetnote, resides in the WordPress REST API&#8217;s batch endpoint. Introduced in WordPress version 5.6 in November 2020, the batch endpoint allows for multiple sub-requests to be processed within a single HTTP request. The flaw lies in how WordPress manages these sub-requests, particularly when errors occur. When an error in one sub-request disrupts the internal tracking arrays used to manage parallel requests, it can cause a one-step desynchronization. This desynchronization can lead to a subsequent request being processed by an unintended handler, effectively bypassing security checks and access controls. The vulnerability specific to this route confusion was introduced with the release of WordPress 6.9.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"CVE-2026-60137_SQL_Injection_in_WordPress_Core\"><\/span>CVE-2026-60137: SQL Injection in WordPress Core<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>This SQL injection vulnerability is a more foundational flaw, impacting a broader range of WordPress versions. It was identified as residing within the <code>WP_Query<\/code> class, specifically in how it handles the <code>author__not_in<\/code> parameter. Normally, this parameter expects an array of author IDs to exclude from query results. However, if an attacker provides a string value instead of an array, the validation check is skipped. This allows the raw, attacker-controlled string to be directly injected into the SQL query, enabling attackers to manipulate database queries, potentially extracting sensitive information or even altering data. This SQL injection vulnerability dates back to WordPress version 6.8.<\/p>\n<h4><span class=\"ez-toc-section\" id=\"The_Chained_Exploitation\"><\/span>The Chained Exploitation<span class=\"ez-toc-section-end\"><\/span><\/h4>\n<p>The power of wp2shell comes from combining these two vulnerabilities. An unauthenticated attacker first exploits the REST API batch-route confusion (CVE-2026-63030) to bypass authentication and gain access to internal WordPress functions. This access allows them to target the <code>WP_Query<\/code> class and specifically manipulate the <code>author__not_in<\/code> parameter. By providing a malformed string, they trigger the SQL injection (CVE-2026-60137), allowing them to execute arbitrary SQL commands. In a full remote code execution (RCE) scenario, this SQL injection can be leveraged to write malicious files to the server or manipulate existing files, ultimately leading to arbitrary code execution.<\/p>\n<figure class=\"article-inline-figure\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiRULLT1q8L6AtUB7jgKywi_KSF8VGKkOF9yC3Snt81K1aD2XSEV1jgfIe331rXUWGqhmAyFgr1USssr4_CQmuE7HLAn0ShaQ0pHY_yvNYMjQdHtpV8i-vlk2ickhJSJDSN3amGox_DMR5hemMlrgXIk8kHoHlYKZncjpiV3ibF77ax1Yn0fEjxtgxy7tY\/s1700-e365\/wordpress-core.jpg\" alt=\"New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code\" class=\"article-inline-img\" loading=\"lazy\" \/><\/figure>\n<h3><span class=\"ez-toc-section\" id=\"Scope_of_Vulnerability_and_Patching_Efforts\"><\/span>Scope of Vulnerability and Patching Efforts<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The effective range of the wp2shell exploit is critical for understanding the threat landscape. The SQL injection vulnerability (CVE-2026-60137) has a deeper historical reach, affecting WordPress versions from 6.8 onwards. However, the critical RCE chain, which requires the REST API batch-route confusion, is present only in WordPress versions 6.9 and later. This means that sites running version 6.8 are vulnerable to the SQL injection but not the full RCE chain via this specific mechanism.<\/p>\n<p>WordPress released patches to address these vulnerabilities:<\/p>\n<ul>\n<li><strong>WordPress 6.9.5<\/strong> (released Friday, July 17, 2026) addresses both vulnerabilities for sites running the 6.9 branch.<\/li>\n<li><strong>WordPress 7.0.2<\/strong> (released Friday, July 17, 2026) addresses both vulnerabilities for sites running the 7.0 branch.<\/li>\n<li><strong>WordPress 6.8.6<\/strong> (released Friday, July 17, 2026) addresses the SQL injection vulnerability (CVE-2026-60137) for sites still running the older 6.8 branch, though it does not contain the batch-route confusion flaw.<\/li>\n<li><strong>WordPress 7.1 beta2<\/strong> has also been updated to include both fixes.<\/li>\n<\/ul>\n<p>WordPress implemented what it refers to as &quot;forced updates&quot; through its auto-update system for these critical patches. This measure was taken to ensure the widest possible coverage given the severity of the threat. However, it remains unclear whether these forced updates reached sites where users had explicitly disabled the auto-update functionality. Administrators are strongly advised to verify their current WordPress version directly rather than relying solely on the assumption that the update has been applied.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Background_and_Discovery\"><\/span>Background and Discovery<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The discovery of wp2shell highlights the ongoing cat-and-mouse game between security researchers and software vendors. Searchlight Cyber&#8217;s detailed write-up, released on July 17, 2026, provides a comprehensive technical analysis. While Searchlight is withholding its own in-depth technical report for a limited period, a dedicated checker website, wp2shell.com, has been made available for site owners to assess their vulnerability status.<\/p>\n<p>The rapid dissemination of exploit details is a common trend in the cybersecurity world. Despite Searchlight&#8217;s initial reticence, the release of the patch itself, with its changed files clearly documented, provided enough information for other researchers to reverse-engineer the mechanism. Within a short period, the full exploit chain was published, and a functional proof-of-concept appeared on GitHub, accelerating the potential for widespread exploitation.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Broader_Implications_and_Analysis\"><\/span>Broader Implications and Analysis<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>With an estimated 500 million websites running on WordPress globally, the potential impact of this vulnerability is significant. However, the RCE chain is specifically tied to versions 6.9 and above, which were released after December 2, 2025. This narrows the directly exposed population to sites running relatively recent versions of WordPress, though the exact number remains unspecified.<\/p>\n<p>The scoring of these vulnerabilities presents an interesting dichotomy. WordPress&#8217;s own advisory rates the full RCE chain as &quot;Critical.&quot; However, its official CVE record scores it at 7.5 (High), with impact metrics focusing solely on data access, not the integrity or availability losses typically associated with code execution. The SQL injection component, on its own, receives a score higher than 9.1 (Critical). This discrepancy suggests that the scoring system may not fully capture the cascading effects of the chained exploit. Security professionals are advised to track both CVEs independently rather than relying on a single label.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"A_Persistent_Object_Cache_Condition\"><\/span>A Persistent Object Cache Condition<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>A notable condition that can mitigate the risk of the full RCE path is the presence of a persistent object cache. According to Cloudflare, which also released Web Application Firewall (WAF) rules alongside the disclosure, the code execution path is only viable when a site is <em>not<\/em> running a persistent object cache. This means that default WordPress installations, which typically do not employ such caching mechanisms, remain fully exposed to the RCE attack. Sites utilizing Redis or Memcached as persistent object caches might be protected from this specific RCE vector, but this does not offer protection against the underlying SQL injection vulnerability.<\/p>\n<figure class=\"article-inline-figure\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" alt=\"New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code\" class=\"article-inline-img\" loading=\"lazy\" \/><\/figure>\n<h3><span class=\"ez-toc-section\" id=\"Official_Responses_and_Industry_Reactions\"><\/span>Official Responses and Industry Reactions<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>As of July 18, 2026, the wp2shell vulnerabilities were not yet listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, which requires confirmed instances of exploitation. No public reports of active exploitation had emerged by this date. However, this lack of immediate exploitation does not diminish the threat, especially given the public availability of the exploit.<\/p>\n<p>Security scanner providers are moving quickly to incorporate detection. Rapid7 announced that authenticated checks for InsightVM and Nexpose would be available by July 20, 2026. The cybersecurity industry has seen a surge in mass exploitation campaigns, often targeting WordPress. For instance, a previous vulnerability in a caching plugin, exploited before its server was compromised in June 2026, allowed the &quot;WP-SHELLSTORM&quot; group to compromise over 17,000 sites. The wp2shell vulnerability, being present in core and exploitable on default settings, presents a potentially broader and more immediate threat.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"Mitigations_for_Unpatched_Systems\"><\/span>Mitigations for Unpatched Systems<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>For website administrators unable to update their WordPress installation immediately, Searchlight Cyber has outlined several temporary mitigation strategies. These primarily focus on preventing anonymous access to the batch endpoint.<\/p>\n<ul>\n<li><strong>Web Application Firewall (WAF) Rules:<\/strong> Implementing WAF rules to block requests to <code>\/wp-json\/batch\/v1<\/code> from unauthenticated users. This is a crucial step, as it directly targets the entry point for the RCE chain.<\/li>\n<li><strong>Disabling the Batch Endpoint:<\/strong> If not essential for legitimate site functionality, disabling the batch endpoint entirely through configuration or custom code could prevent exploitation. However, this carries the risk of breaking legitimate integrations that rely on this feature.<\/li>\n<li><strong>Rate Limiting:<\/strong> Implementing aggressive rate limiting on the batch endpoint can make it more difficult for attackers to scan and exploit vulnerable sites effectively, although it does not prevent exploitation altogether.<\/li>\n<\/ul>\n<p>These are considered stopgap measures, and updating WordPress to the latest patched version remains the only definitive solution. The open-source nature of WordPress means that once a patch is released, the information required to understand and exploit the vulnerability is readily available. The race to patch is therefore paramount.<\/p>\n<h3><span class=\"ez-toc-section\" id=\"The_Race_Against_Time\"><\/span>The Race Against Time<span class=\"ez-toc-section-end\"><\/span><\/h3>\n<p>The disclosure of wp2shell underscores a critical dynamic in cybersecurity: the race between vulnerability patching and exploit development. WordPress&#8217;s decision to implement forced updates signals the extreme concern surrounding these flaws. However, the speed at which the exploit mechanism was published and a proof-of-concept developed demonstrates the agility of the threat actor community.<\/p>\n<p>The ultimate impact of wp2shell will be determined by two key metrics: the speed at which WordPress sites adopt the patches and the rate at which attackers begin actively scanning for and exploiting vulnerable systems. The widespread adoption of WordPress, coupled with the critical nature of remote code execution vulnerabilities, places immense pressure on site owners to act swiftly. The coming days and weeks will reveal the true extent of this threat and how effectively the WordPress ecosystem responds to this significant security challenge.<\/p>\n<!-- RatingBintangAjaib -->","protected":false},"excerpt":{"rendered":"<p>July 18, 2026 \u2013 A critical security vulnerability within the core of WordPress, dubbed &quot;wp2shell,&quot; has been fully detailed, revealing a two-part exploit chain that allows anonymous attackers to execute arbitrary code on vulnerable websites. Initially flagged by researchers, the vulnerabilities have now been assigned CVE identifiers, the complete exploitation mechanism has been published, and &hellip;<\/p>\n","protected":false},"author":27,"featured_media":6452,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[108],"tags":[2857,2858,2808,669,1524,109,1273,603,111,110,2805,995,2753],"class_list":["post-6453","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-protection","tag-allows","tag-anonymous","tag-chained","tag-code","tag-core","tag-cybersecurity","tag-execution","tag-exploits","tag-privacy","tag-security","tag-shell","tag-vulnerability","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/posts\/6453","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=6453"}],"version-history":[{"count":0,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/posts\/6453\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=\/wp\/v2\/media\/6452"}],"wp:attachment":[{"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=6453"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=6453"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lockitsoft.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=6453"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}