WordPress Under Siege: Attackers Chain Core Flaws for Rapid Site Takeovers

Attackers wasted no time hammering two chained flaws in WordPress core that deliver unauthenticated remote code execution. Patches dropped Friday, but exploitation began within hours, creating backdoors and deploying malware across thousands of sites. Administrators must update immediately and audit for compromise.
WordPress Under Siege: Attackers Chain Core Flaws for Rapid Site Takeovers
Written by Sara Donnelly

WordPress powers more than 40 percent of the web. That reach makes it a perennial target. This week the stakes rose sharply.

Just hours after the project shipped emergency patches late Friday, attackers began pounding away at two vulnerabilities in the core software. Chain them together and you get unauthenticated remote code execution on stock installations with no plugins required. The Register first broke details of the frenzied activity on Monday.

Researchers reproduced the bugs quickly. Some suspect frontier AI models helped accelerate the process. “Once the vulnerabilities were publicly disclosed, reproducing them with the help of frontier AI models was only a matter of time and tokens,” Jake Knott, principal security researcher at watchTowr, told The Register. “WatchTowr was able to trivially reproduce CVE-2026-63030 within minutes of disclosure, and the second CVE-2026-60137 with some additional effort.”

Exploitation started almost immediately. By early Saturday morning, attackers used public proof-of-concept code to pull hashed credentials first. Full remote code execution followed as more details leaked. Honeypots lit up. Tens of thousands of attempts poured in. More than 100 backdoor administrator accounts appeared across monitored environments, created through variations on that public tooling.

Attackers didn’t stop at accounts. They dropped fake plugins. Some delivered further remote code execution. Others siphoned credentials or secrets. In at least one observed case, a threat actor kept trying to download Overlord, a Golang-based remote access trojan. The activity crossed every organization size and industry vertical that watchTowr tracks.

The flaws carry different labels. CVE-2026-60137 counts as a moderate SQL injection. CVE-2026-63030 earns critical status for a REST API batch-route confusion problem. Adam Kues at Searchlight Cyber found and reported the latter. He dubbed the overall chain wp2shell.

“The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins,” Kues stated in his advisory. His team also released a free checker tool at wp2shell.com so administrators can test their setups without waiting for updates.

Route confusion sits at the heart of the batch endpoint trouble. Hacktron researchers explained it this way on their blog: a flaw causes the arrays holding sub-requests, validation results, and matched handlers to fall out of alignment. WordPress then treats unvalidated requests as trusted. Alone each bug resists easy exploitation. Together they open the door wide.

Versions matter. WordPress 6.9 suffers from both issues. The 6.9.5 release fixes them. Version 6.8 faces only the SQL injection and receives its repair in 6.8.6. The 7.0 series required the 7.0.2 emergency update. Even the 7.1 beta carried the bugs until beta 2. Anything before 6.8 stayed safe.

The WordPress security team moved fast. They forced automatic updates for all affected sites. John Blackbourn, a core developer, put it plainly in the official announcement. He urged users to “update your sites immediately.” The WordPress.org announcement credits multiple contributors for spotting the SQL injection, including TF1T, dtro, and haongo. It singles out Adam Kues for the REST API work that led to the full remote code execution chain.

Yet speed of patching didn’t outrun the attackers. VulnCheck analysts verified more than two dozen unique proof-of-concept exploits by Sunday. PatchStack noted active exploitation the same night the fixes dropped. And recent reporting from The Hacker News and other outlets confirms the window between disclosure and widespread abuse has shrunk to hours in many cases.

This episode fits a larger pattern. Security research firm Patchstack documented 11,334 new vulnerabilities in the WordPress ecosystem throughout 2025. That figure marked a 42 percent jump from the year before. High-severity issues and those ripe for real-world attacks both climbed sharply. Many plugins and themes lag behind core update cycles, leaving sites exposed even when the foundation looks solid.

AI’s role adds a fresh wrinkle. Multiple researchers on X noted that models like GPT-5.6 Sol Ultra can surface these kinds of chains for modest compute costs. One post highlighted a $25 experiment that uncovered a pre-auth remote code execution path. Exploit brokers reportedly pay up to $500,000 for such finds. The economics have flipped. Discovery that once demanded elite teams now fits in an afternoon’s cloud budget.

Defenders face a clear checklist. Update first. Then inspect. “Defenders need to inspect their WordPress instances for new administrator accounts, malicious plugins, or other suspicious files, regardless of whether they’ve patched,” Knott warned. Honeypot data showed indiscriminate scanning across the public internet. Anything reachable drew probes.

Organizations that delayed until Monday almost certainly host intruders already. The combination of core-level access, no authentication barrier, and rapid public exploit development leaves little margin. Temporary workarounds existed before patches arrived. Blocking anonymous access to the /wp-json/batch/v1 endpoint bought time for some. But that fix never scaled to the entire installed base.

WordPress has improved its update machinery over the past decade. Forced auto-updates helped contain this outbreak faster than in earlier eras. Still, the platform’s massive footprint means millions of sites run outdated versions or custom configurations that skip automatic changes. Plugin and theme vulnerabilities continue to outpace core fixes in volume.

Security firms continue to track post-exploitation behavior. Some attackers focus on credential theft for resale. Others deploy malware or build botnets. A few simply deface pages for notoriety. The variety reflects the broad attacker pool drawn by easy-to-use public code.

WatchTowr, VulnCheck, and Searchlight Cyber have all published additional analysis since the initial wave. Their collective data paints a picture of sustained pressure rather than a one-day spike. New articles from today, including coverage on BreachNews and Rapid7’s blog, detail how proof-of-concept volume exploded over the weekend and warn that unpatched instances should be presumed compromised.

The incident carries lessons that stretch beyond one CMS. When core software that underpins a huge slice of the internet ships a pre-auth remote code execution path, response times compress. Disclosure, reproduction, exploit publication, and mass scanning now occur inside a single weekend. AI assistance only tightens that timeline further.

Site operators cannot treat updates as optional maintenance anymore. They form the first and often only line between continued operation and silent takeover. And even after patching, forensic review becomes mandatory. The backdoors installed during the initial rush will linger if nobody looks for them.

WordPress itself shows no signs of shrinking. Its 7.0 release arrived in May with new collaboration features and deeper AI hooks. Those additions expand the attack surface even as the project races to close holes. The tension between innovation and security will persist.

For now the immediate task is cleanup. Check your version. Apply the patch if you haven’t. Hunt for rogue admin accounts and unfamiliar plugins. Then consider longer-term steps such as stricter plugin vetting, regular integrity scans, and perhaps web application firewall rules tuned to the batch endpoint. The attackers have already moved on to the next vulnerable target. Don’t give them an easy win.

Subscribe for Updates

CybersecurityUpdate Newsletter

The CybersecurityUpdate Email Newsletter is your essential source for the latest in cybersecurity news, threat intelligence, and risk management strategies. Perfect for IT security professionals and business leaders focused on protecting their organizations.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us