Home » News-posts » Patched WordPress Bugs Turn into a Nightmare as Hackers Exploit Freshly Fixed Flaws
Patched WordPress Bugs
SecureTech

Patched WordPress Bugs Turn into a Nightmare as Hackers Exploit Freshly Fixed Flaws

Cybersecurity researchers are warning WordPress website owners to update their installations immediately. The alert became prominent after attackers began exploiting two recently patched core vulnerabilities just days after security fixes were released. The attacks target unpatched websites running vulnerable versions of WordPress and could allow threat actors to remotely execute malicious code without authentication. The incident has put millions of websites at risk.

The vulnerabilities, tracked as CVE-2026-60137 and CVE-2026-63030, were addressed in the WordPress 7.0.2 security release published on July 17. The WordPress security team classified the issues as one high-severity SQL injection flaw and one critical remote code execution (RCE) vulnerability.

Observing the seriousness of the flaws, WordPress enabled forced automatic updates for supported versions wherever possible and urged administrators to install the patches without delay.

Exploitation Resumed Within Hours of Patch Release

The security fixes of WordPress to patch CVE-2026-60137 and CVE-2026-63030 did not stop attackers from moving quickly. Findings reveal that exploitation attempts began almost immediately after technical details, and proof-of-concept information became public. Threat actors scanning the internet for vulnerable WordPress websites have not yet installed the latest updates.

As per estimations, tens of millions of websites built on WordPress could remain exposed if administrators delay updates. Successful exploitation could have widespread consequences for businesses, publishers, e-commerce platforms, and personal blogs as WordPress powers a significant share of websites globally.

Two Patched WordPress Bugs Can Cause a Greater Impact:

The first vulnerability, CVE-2026-60137, is an unauthenticated SQL injection flaw affecting WordPress versions 6.8 and later. The second, CVE-2026-63030, impacts versions 6.9 and later and allows unauthenticated remote code execution through the WordPress REST API under specific conditions.

Attackers can chain the SQL injection flaw with the RCE vulnerability to gain complete control of a targeted website without requiring login credentials. This attack chain is widely referred to by researchers as wp2shell. It can significantly raise the potential impact because compromised servers can be used to deploy malware, steal sensitive information, create administrator accounts, or establish persistent backdoors.

How Did WordPress React to the Vulnerabilities?

Recognizing the severity of the flaws, the WordPress project released version 7.0.2. Alongside that, it released backported security updates for supported branches, including versions 6.9.5 and 6.8.6. The organization also activated forced automatic updates for eligible websites, which is an uncommon step reserved for its highest-priority security issues.

WordPress highlighted that administrators should still verify that their websites have successfully updated, as some environments may disable automatic updates or require manual intervention.

As active exploitation is already underway, cybersecurity experts recommend that organizations immediately confirm their WordPress version. Apart from that, the application of the latest security release, the review of the administrator accounts for unauthorized changes, and monitoring server logs for suspicious activity will benefit site owners.

HiTechNectar evaluates leading tech trends, cybersecurity insights, and industry best practices. Explore the latest tech and cybersecurity updates with us.


Also Read:

Scaling WordPress for Enterprise Traffic: Patterns & Challenges

Agentic AI Security Risks: What Enterprises Must Prepare For

Subscribe Now

    We send you the latest trends and best practice tips for online customer engagement:


    Receive Updates:




    We hate spams too, you can unsubscribe at any time.