Threat Response - RCE in WordPress Core (wp2shell)
Dutch follows English
On July 20th 2026 WordPress disclosed two critical vulnerabilities that allow attackers to take complete control over WordPress websites without needing any login credentials [1]. Given the severity of the vulnerabilities, WordPress urges users to update to version 7.0.2 or 6.9.5 as soon as possible.
Description
Two serious security flaws affect WordPress websites running versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 of WordPress, tracked under CVE-2026-60137 [2] and CVE-2026-63030 [3]. In addition, WordPress version 6.8.5 and earlier 6.8 versions are also affected by CVE-2026-60137. The most serious vulnerability (CVE-2026-63030) allows attackers to remotely execute malicious code on WordPress websites by simply sending a specially crafted web request to the site's batch API. No username or password is required. The second vulnerability (CVE-2026-60137) enables SQL injection attacks.
Together, these flaws can give attackers complete control over affected websites, allowing them to steal data, deface pages, distribute malware, or use the site for further attacks.
Impact
We estimate the impact of these vulnerabilities as HIGH.
If exploited, attackers can gain complete control over your WordPress website. This means they could:
- Steal sensitive customer data, credentials, or business information
- Modify or delete website content
- Install malware or ransomware
- Use your website to attack others
- Damage your organization's reputation
- Cause business disruption and downtime
Risk
We estimate the risk of these vulnerabilities as HIGH, as the attack requires no preconditions and can be exploited by an unauthenticated attacker on a stock install of WordPress [4]. Furthermore, as proof-of-concept code has been released [5], widespread exploitation is likely.
Mitigation
WordPress has released security updates that fix these vulnerabilities. Organizations should immediately update to the following versions [1]:
- WordPress 7.0.2 (if running version 7.0.x)
- WordPress 6.9.5 (if running version 6.9.x)
- WordPress 6.8.6 (if running version 6.8.x)
- Note that WordPress 6.8 is only affected by CVE-2026-60137
If you are running the beta release of WordPress 7.1, you should update to version 7.1 beta2 immediately.
WordPress has additionally forced automatic updates for sites running the affected versions where automatic updates are enabled.
If patching is not possible in your environment, Searchlight Cyber, who initially reported this vulnerability, have also provided the following temporary workarounds [4]:
- Installing the “Disable WP REST API” plugin to disable unauthenticated users from using the API. This might break functionality for your WordPress instance.
- Using a Web Application Firewall to block both the “/wp-json/batch/v1” path and “?rest_route=/batch/v1” query parameter
What should you do?
You should apply the security updates applicable for your WordPress installation immediately, or apply the mitigations if patching is not possible for your WordPress instance. In addition, Searchlight Cyber has also released a tool to verify whether your WordPress installation is vulnerable: https[:]//wp2shell[.]com/ [4].
Eye Security has additionally also released the following indicators of compromise based on currently available proof-of-concepts for the vulnerability [5, 6]:
- Rogue admin login credentials: prefixed by “wp2_” or “w2s_”
- Rogue admin email domains: “@wp2shell.invalid”, “@wp2shell.shellcode.lol”
- Usage of the exploit endpoints “/wp-json/batch/v1” and “?rest_route=/batch/v1”
- Artifacts in the database as outlined below
Eye Security provides the following locations to verify for presence of the indicators of compromise [6]. Please keep in mind that the absence of indicators does not mean compromise did not take place:
- Within the database, inspect the “wp_users” and “wp_usermeta” tables for unexpected entries, and the “wp_options” table for tampered “active_plugins”, “siteurl/home” and other tampered entries.
- Inspect the “/var/www/html” (or the site’s docroot) for any modified or newly created (PHP) files
- Verify the web server access logs for any accesses to the endpoints as listed in the indicators of compromise list
- Verify the “/var/lib/php/sessions/” and “/tmp” folders for indications of dropped payloads or staging files
- Verify the system’s authentication logs for any unauthorised authentication attempts, the shell history of the WordPress/”www-data” service accounts for any malicious entries, and the crontab for any unauthorised entries
When in doubt about any entries, please do not hesitate to reach out to our SOC for further assistance.
What will Northwave do?
We will monitor any developments regarding this vulnerability. If new critical information about this threat arises we will reach out to you. You can contact us by phone or send us an email if you would like additional information.
E-mail: soc@northwave-cybersecurity.com
Do you have an incident right now? Call our Incident Response Team: 00800 1744 0000
Disclaimer applies, see below.
Sources
[1] https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-60137
[3] https://nvd.nist.gov/vuln/detail/CVE-2026-63030
[4] https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core
[5] https[:]//github[.]com/Icex0/wp2shell-poc
[6] https://research.eye.security/wp2shell-defenders-guide/
Op 20 juli 2026 heeft WordPress twee kritieke kwetsbaarheden bekendgemaakt waarmee aanvallers volledige controle over WordPress-websites kunnen verkrijgen zonder inloggegevens nodig te hebben [1]. Gezien de ernst van deze kwetsbaarheden roept WordPress gebruikers op om zo snel mogelijk te updaten naar versie 7.0.2 of 6.9.5.
Beschrijving
Twee ernstige beveiligingslekken treffen WordPress-websites die draaien op versies 6.9.0 tot en met 6.9.4 en 7.0.0 tot en met 7.0.1 van WordPress. De kwetsbaarheden zijn geregistreerd onder CVE-2026-60137 [2] en CVE-2026-63030 [3]. Daarnaast worden WordPress-versie 6.8.5 en eerdere 6.8 versies eveneens getroffen door CVE-2026-60137.
De meest ernstige kwetsbaarheid (CVE-2026-63030) stelt aanvallers in staat om op afstand kwaadaardige code uit te voeren op WordPress-websites door simpelweg een speciaal geconfigureerd webverzoek naar de batch-API van de website te sturen. Hiervoor zijn geen gebruikersnaam of wachtwoord vereist. De tweede kwetsbaarheid (CVE-2026-60137) maakt SQL-injectieaanvallen mogelijk.
Gezamenlijk kunnen deze kwetsbaarheden aanvallers volledige controle geven over getroffen websites. Hierdoor kunnen zij gegevens stelen, pagina's aanpassen of vervangen, malware verspreiden of de website gebruiken voor verdere aanvallen.
Impact
Wij schatten de impact van deze kwetsbaarheden in als HOOG.
Indien misbruikt kunnen aanvallers volledige controle verkrijgen over uw WordPress-website. Dit betekent dat zij:
- Gevoelige klantgegevens, inloggegevens of bedrijfsinformatie kunnen stelen
- Website-inhoud kunnen wijzigen of verwijderen
- Malware of ransomware kunnen installeren
- Uw website kunnen gebruiken om anderen aan te vallen
- De reputatie van uw organisatie kunnen schaden
- Bedrijfsverstoringen en downtime kunnen veroorzaken
Risico
Wij schatten het risico van deze kwetsbaarheden in als HOOG, aangezien de aanval geen randvoorwaarden kent en kan worden uitgevoerd door een niet-geauthenticeerde aanvaller op een standaardinstallatie van WordPress [4]. Daarnaast is proof-of-concept-code openbaar beschikbaar gesteld [5], waardoor grootschalig misbruik waarschijnlijk is.
Mitigatie
WordPress heeft beveiligingsupdates uitgebracht die deze kwetsbaarheden verhelpen. Organisaties dienen onmiddellijk te updaten naar een van de volgende versies
- WordPress 7.0.2 (indien u versie 7.0.x gebruikt)
- WordPress 6.9.5 (indien u versie 6.9.x gebruikt)
- WordPress 6.8.6 (indien u versie 6.8.x gebruikt)
- Let op: WordPress 6.8 wordt uitsluitend getroffen door CVE-2026-60137
Indien u gebruikmaakt van de bètaversie van WordPress 7.1, dient u onmiddellijk te updaten naar versie 7.1 beta2.
Daarnaast heeft WordPress automatische updates afgedwongen voor websites die een getroffen versie gebruiken en waarbij automatische updates zijn ingeschakeld.
Indien patchen niet mogelijk is, heeft Searchlight Cyber, de partij die deze kwetsbaarheid oorspronkelijk heeft gemeld, de volgende tijdelijke workarounds gepubliceerd
- Installeer de plugin "Disable WP REST API" om niet-geauthenticeerde gebruikers de toegang tot de API te ontzeggen. Houd er rekening mee dat dit functionaliteit van uw WordPress-installatie kan verstoren.
- Gebruik een Web Application Firewall (WAF) om zowel het pad "/wp-json/batch/v1" als de queryparameter "?rest_route=/batch/v1" te blokkeren.
Wat moet u doen?
U dient de beveiligingsupdates die van toepassing zijn op uw WordPress-installatie onmiddellijk te installeren, of de hierboven beschreven mitigerende maatregelen toe te passen wanneer patchen niet mogelijk is. Daarnaast heeft Searchlight Cyber een hulpmiddel beschikbaar gesteld waarmee kan worden gecontroleerd of uw WordPress-installatie kwetsbaar is: https[:]//wp2shell[.]com/ [4].
Eye Security heeft daarnaast de volgende indicators of compromise (IoC's) gepubliceerd op basis van de momenteel beschikbare proof-of-concepts voor deze kwetsbaarheid [5, 6]:
- Malafide beheerdersaccounts met gebruikersnamen die beginnen met "wp2_" of "w2s_"
- Malafide beheerdersaccounts met de e-maildomeinen "@wp2shell.invalid" of "@wp2shell.shellcode.lol"
- Gebruik van de exploit-endpoints "/wp-json/batch/v1" en "?rest_route=/batch/v1"
- Artefacten in de database zoals hieronder beschreven
Eye Security adviseert de volgende locaties te controleren op aanwezigheid van deze indicators of compromise [6]. Houd er rekening mee dat het ontbreken van indicatoren niet betekent dat er geen compromittering heeft plaatsgevonden:
- Controleer in de database de tabellen "wp_users" en "wp_usermeta" op onverwachte toevoegingen, evenals de tabel "wp_options" op gemanipuleerde waarden zoals "active_plugins", "siteurl/home" en andere gewijzigde instellingen.
- Controleer de map "/var/www/html" (of de documentroot van de website) op gewijzigde of nieuw aangemaakte (PHP-)bestanden.
- Controleer de webserver-accesslogs op verzoeken naar de endpoints die zijn opgenomen in de lijst met indicators of compromise.
- Controleer de mappen "/var/lib/php/sessions/" en "/tmp" op aanwijzingen van geplaatste payloads of staging-bestanden.
- Controleer de authenticatielogs van het systeem op ongeautoriseerde aanmeldingen, de shellgeschiedenis van de WordPress-/"www-data"-serviceaccounts op verdachte opdrachten en de crontab op ongeautoriseerde vermeldingen.
Wanneer u twijfelt over bepaalde bevindingen, aarzel dan niet om contact op te nemen met onze SOC voor verdere ondersteuning.
Wat zal Northwave doen?
Northwave houdt de ontwikkelingen omtrent deze kwetsbaarheid in de gaten. Als er belangrijke nieuwe informatie omtrent deze dreiging bekend wordt, stellen wij u hiervan op de hoogte. Als u behoefte heeft aan extra informatie zijn we zowel telefonisch als via email bereikbaar.
E-mail: soc@northwave-cybersecurity.com
Heeft u op dit moment een incident? Bel ons Incident Response Team: 00800 1744 0000
Disclaimer van toepassing, zie hieronder.
Bronnen
[1] https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-60137
[3] https://nvd.nist.gov/vuln/detail/CVE-2026-63030
[4] https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core
[5] https[:]//github[.]com/Icex0/wp2shell-poc
[6] https://research.eye.security/wp2shell-defenders-guide/

