Security Alert: Critical WordPress (WP2Shell) Vulnerabilities Under Active Exploitation
Critical WordPress Core vulnerabilities, known as WP2Shell and identified as CVE-2026-60137 and CVE-2026-63030, are being actively exploited by attackers to gain unauthorized access to vulnerable WordPress websites.
Affected Systems:
The following WordPress versions are affected:
WordPress versions: 6.8.0 – 6.8.5
WordPress versions: 6.9.0 – 6.9.4
WordPress versions: 7.0.0 – 7.0.1
Security Risks
Successful exploitation of these vulnerabilities could allow unauthenticated attackers to gain administrative privileges, execute arbitrary code remotely, create unauthorized administrator accounts, and take full control of affected WordPress websites.
For the full list of security updates released by WordPress, please refer to the official WordPress security releases.
Recommended Actions
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
1. Update affected WordPress installations as soon as possible to the latest supported versions to address these vulnerabilities and reduce the risk of exploitation.
Upgrade WordPress to the latest supported fixed versions:
WordPress versions 6.8.0 – 6.8.5: Upgrade to version 6.8.6 or above
WordPress versions 6.9.0 – 6.9.4: Upgrade to version 6.9.5 or above
WordPress versions 7.0.0 – 7.0.1: Upgrade to version 7.0.2 or above
2. Before updating or patching, please ensure that you have the latest backup that can easily be restored.
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.