Hackers are actively breaking into websites running outdated versions of WordPress following the discovery and public disclosure of two critical security flaws that allow attackers to take full remote control of a vulnerable site. WordPress has now patched both vulnerabilities, urging site administrators to update immediately and enabling forced updates where possible.
The attacks are fueled by the ready availability of numerous proof-of-concept exploits for the two bugs, identified as CVE-2026-60137 and CVE-2026-63030.
According to WordPress's own statistics, more than 400 million websites run those affected versions, though that figure does not account for sites already patched since the disclosure. The flaws affect versions 6.9.0 through 6.9.4, and 7.0.0 through 7.0.1. According to WordPress's own statistics, more than 400 million websites run those affected versions, though that figure does not account for sites already patched since the disclosure.
One of the two bugs, dubbed WP2Shell and discovered by Adam Kues of Searchlight Cyber, enables remote shell access when paired with the second vulnerability. The researcher credited WordPress for pushing automatic updates, Cloudflare for blocking attacks against unpatched sites, and web application firewalls for limiting successful breaches.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




