Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Security Alert: Critical WordPress (WP2Shell) Vulnerabilities Under Active Exploitation

Critical WordPress Core vulnerabilities, known as WP2Shell and identified as CVE-2026-60137 and CVE-2026-63030, are being actively exploited by attackers to gain unauthorized access to vulnerable WordPress websites.
 
Affected Systems:
 
The following WordPress versions are affected:
  • WordPress versions: 6.8.0 – 6.8.5
  • WordPress versions: 6.9.0 – 6.9.4
  • WordPress versions: 7.0.0 – 7.0.1
 
Security Risks
 
Successful exploitation of these vulnerabilities could allow unauthenticated attackers to gain administrative privileges, execute arbitrary code remotely, create unauthorized administrator accounts, and take full control of affected WordPress websites.


For the full list of security updates released by WordPress, please refer to the official WordPress security releases.
 
Recommended Actions
 
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
 
1. Update affected WordPress installations as soon as possible to the latest supported versions to address these vulnerabilities and reduce the risk of exploitation.
 

Upgrade WordPress to the latest supported fixed versions:
 
  • WordPress versions 6.8.0 – 6.8.5: Upgrade to version 6.8.6 or above
  • WordPress versions 6.9.0 – 6.9.4: Upgrade to version 6.9.5 or above
  • WordPress versions 7.0.0 – 7.0.1: Upgrade to version 7.0.2 or above 
 
2. Before updating or patching, please ensure that you have the latest backup that can easily be restored.
 
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.
 
References

21 July 2026

© 2026 National Cyber Security Authority