WordPress 7.0.2 patches WP2Shell unauthenticated RCE | already exploited in the wild, tens of millions of sites exposed
TL;DR
WordPress shipped 7.0.2 on July 17, patching the WP2Shell chain — CVE-2026-60137 and CVE-2026-63030. The critical bug is an unauthenticated SQL injection through the REST API batch endpoint; Patchstack confirmed the chain leads to RCE and full site takeover. Tens of millions of sites remained unpatched as of July 20.
WordPress on July 17 shipped 7.0.2 as a security release, fixing the WP2Shell vulnerability chain — CVE-2026-60137 and CVE-2026-63030. The critical bug is an unauthenticated SQL injection in the REST API batch endpoint, via route/handler confusion defeating input validation. Patchstack confirmed the full chain leads to remote code execution and full site takeover.
Affected versions: WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1. WordPress.org has enabled forced auto-updates for affected sites — a rarely-used escalation.
Patchstack observed in-the-wild exploitation of CVE-2026-63030 starting shortly before 7 PM ET on July 17, and a public PoC has leaked. Hexastrike and WatchTowr both independently warned that attackers are actively taking over sites still running vulnerable WordPress versions — one estimate puts tens of millions of WordPress sites still unpatched as of July 20.
WordPress runs on about 43% of all CMS-powered websites globally — that means 50–80 million exposed sites out there. The REST API batch endpoint is enabled by default and requires no login; the attack surface amounts to "if the site is online, it can be hit." This is WordPress's most severe unauthenticated RCE incident since the 2019 REST API disclosure bug.
Every site on 6.9.x or 7.0.0–7.0.1 needs to update to 7.0.2 immediately. No workaround.
via TechCrunch / Patchstack
Affected versions: WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1. WordPress.org has enabled forced auto-updates for affected sites — a rarely-used escalation.
Patchstack observed in-the-wild exploitation of CVE-2026-63030 starting shortly before 7 PM ET on July 17, and a public PoC has leaked. Hexastrike and WatchTowr both independently warned that attackers are actively taking over sites still running vulnerable WordPress versions — one estimate puts tens of millions of WordPress sites still unpatched as of July 20.
WordPress runs on about 43% of all CMS-powered websites globally — that means 50–80 million exposed sites out there. The REST API batch endpoint is enabled by default and requires no login; the attack surface amounts to "if the site is online, it can be hit." This is WordPress's most severe unauthenticated RCE incident since the 2019 REST API disclosure bug.
Every site on 6.9.x or 7.0.0–7.0.1 needs to update to 7.0.2 immediately. No workaround.
via TechCrunch / Patchstack
