Attackers Mass Exploit Critical WordPress Flaws for Unauthenticated Code Execution
AI-generated from multiple sources. Verify before acting on this reporting.
Fresh reports have emerged confirming the widespread nature of the exploitation campaigns targeting WordPress installations. Multiple independent security entities have now validated the active use of the previously identified vulnerability chain, reinforcing the severity of the threat landscape surrounding CVE-2026-63030 and CVE-2026-60137. These additional confirmations indicate that attackers are continuing to leverage these flaws for unauthenticated remote code execution across a broader range of targets than initially assessed. The convergence of new data points underscores the urgency for site administrators to apply immediate patches or implement compensating controls, as the window for safe operation without mitigation has effectively closed. No changes have been made to the technical description of the vulnerabilities themselves; rather, this development reflects an escalation in observed attack activity and a stronger consensus regarding the active exploitation status among security researchers.
Global cyberattack campaigns targeting vulnerable WordPress installations have surged following the discovery of two critical security flaws allowing unauthenticated remote code execution. The coordinated exploitation, identified on July 21, 2026, leverages vulnerabilities cataloged as CVE-2026-63030 and CVE-2026-60137 to compromise websites without requiring prior user interaction or credentials.
Searchlight Cyber disclosed the existence of an exploit chain combining these two defects. The vulnerability in CVE-2026-63030 serves as a primary entry point, while CVE-2026-60137 facilitates full system control once initial access is granted. This combination enables attackers to execute arbitrary code on affected servers immediately upon detection of the flaw.
The attacks have been observed across multiple continents, with significant activity detected in Switzerland, Germany, the United Kingdom, Indonesia, Lithuania, the Netherlands, and Singapore. Security monitoring firms WatchTowr, Intruder, and Wiz are currently tracking the spread of these exploits as they target a wide range of organizations relying on WordPress content management systems.
The nature of the vulnerabilities allows for mass exploitation without preconditions. Attackers do not need to bypass authentication mechanisms or exploit user behavior; simply sending a crafted request to an unpatched server is sufficient to gain control. This low-barrier entry point has accelerated the pace of infections, with automated tools scanning and compromising thousands of sites in rapid succession.
WordPress installations that have not applied recent security patches remain at immediate risk. The widespread availability of these exploits suggests that threat actors are actively weaponizing the flaws for various purposes, including data theft, ransomware deployment, or establishing botnet infrastructure. Security teams worldwide are rushing to identify and patch affected systems before further damage occurs.
As the campaign continues, questions remain regarding the full extent of the compromise and whether specific sectors have been prioritized by attackers. While Searchlight Cyber has detailed the technical mechanics of the exploit chain, it is unclear if any nation-state actors or organized crime groups are behind the initial discovery and distribution of these tools. The global nature of the attacks indicates a coordinated effort to maximize impact across diverse digital infrastructures.
Administrators are urged to verify their WordPress versions against known vulnerable releases immediately. Without urgent remediation, organizations face the prospect of complete server compromise with minimal resistance from existing security controls.