Skip to content
theregister·

🚨WordPress Patches Critical RCE Bugs; Exploits Ramp Up

Exploits hit WordPress sites within hours of patch release

TL;DR

WordPress released critical patches Friday but attackers quickly exploited the bugs. Over 100 backdoor accounts and tens of thousands of attempts recorded. Any site unpatched by Monday is likely compromised.

WordPress patched two critical vulnerabilities (CVE-2026-63030, CVE-2026-60137) Friday but attackers began exploiting them within hours using public exploit code. Over 100 backdoor accounts and tens of thousands of exploitation attempts were recorded by honeypots. If you're running WordPress, update now or risk compromise. The first bug is a moderate-severity SQL injection issue (CVE-2026-60137), while the second is a critical REST API batch-route confusion flaw (CVE-2026-63030). When chained together, they allow unauthenticated RCE.

WordPress Patches Critical RCE Bugs; Exploits Ramp Up — theregister

Key Points

1

WordPress released patches for CVE-2026-63030 and CVE-2026-60137 on Friday

2

Over 100 backdoor accounts were recorded in honeypots by Sunday

3

Tens of thousands of exploitation attempts detected, using WP2Shell exploits

4

WordPress forced updates via auto-update for sites running affected versions

5

Any site unpatched by Monday is likely already compromised

Why It Matters

If you're running WordPress on any version from 6.9 to 7.1 Beta 1, this affects your security posture. The vulnerabilities allow attackers to gain RCE and exfiltrate credentials or secrets. Any site unpatched by Monday is likely compromised. Inspect for new admin accounts, malicious plugins, or suspicious files.

WordPressCVE-2026-63030CVE-2026-60137RCEpatches

Frequently Asked Questions

Why does this matter?

If you're running WordPress on any version from 6.9 to 7.1 Beta 1, this affects your security posture. The vulnerabilities allow attackers to gain RCE and exfiltrate credentials or secrets. Any site unpatched by Monday is likely compromised. Inspect for new admin accounts, malicious plugins, or suspicious files.

What happened?

WordPress released critical patches Friday but attackers quickly exploited the bugs. Over 100 backdoor accounts and tens of thousands of attempts recorded. Any site unpatched by Monday is likely compromised.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 2,180 builders reading daily.

Also get