{"id":36437,"date":"2026-07-20T10:00:37","date_gmt":"2026-07-20T09:00:37","guid":{"rendered":"https:\/\/www.digife.it\/?p=36437"},"modified":"2026-07-20T08:41:13","modified_gmt":"2026-07-20T07:41:13","slug":"wordpress-red-alert-critical-flaw-wp2shell","status":"publish","type":"post","link":"https:\/\/www.digife.it\/en\/wordpress-red-alert-critical-flaw-wp2shell\/","title":{"rendered":"WordPress Red Alert: Critical &quot;wp2shell&quot; Vulnerability Discovered\u201c"},"content":{"rendered":"<h1 data-path-to-node=\"2\">\u201cwp2shell\u201d vulnerability: Over 500 million WordPress sites at risk of RCE<\/h1>\n<p data-path-to-node=\"3\">A bolt from the blue has shaken the world of web design and cybersecurity. A critical vulnerability has just been identified in the core of <b data-path-to-node=\"3\" data-index-in-node=\"153\">WordPress<\/b> which jeopardizes the safety of more than <b data-path-to-node=\"3\" data-index-in-node=\"209\">500 million websites<\/b> throughout the world. Known by experts as <b data-path-to-node=\"3\" data-index-in-node=\"292\">\u201cwp2shell\u201d<\/b>, this flaw allows unauthenticated attackers to take full control of the site (complete <a href=\"https:\/\/www.cerved.com\/news\/a\/cybersecurity\/account-takeover-una-minaccia-in-crescita-nell-era-digitale\" target=\"_blank\" rel=\"noopener\"><i data-path-to-node=\"3\" data-index-in-node=\"407\">takeover<\/i><\/a>) without needing any credentials.<\/p>\n<p data-path-to-node=\"4\">Given the very high level of danger, the WordPress.org team has already started the release of <b data-path-to-node=\"4\" data-index-in-node=\"93\">emergency patches forcing automatic updates<\/b>.<\/p>\n<p data-path-to-node=\"5\">Here&#039;s everything you need to know and how to secure your business or e-commerce website.<\/p>\n<h2 data-path-to-node=\"7\"><\/h2>\n<h2 data-path-to-node=\"7\">What is the \u201cwp2shell\u201d vulnerability and why is it so dangerous?<\/h2>\n<p data-path-to-node=\"8\">The vulnerability was discovered by researcher Adam Kues of the Assetnote team (Searchlight Cyber). Unlike most security issues affecting WordPress\u2014often related to outdated third-party plugins or themes\u2014 <b data-path-to-node=\"8\" data-index-in-node=\"245\">wp2shell resides directly in the CMS core<\/b>.<\/p>\n<p data-path-to-node=\"9\">The attack exploits a confusion flaw in the batch routes of <b data-path-to-node=\"9\" data-index-in-node=\"67\">REST API<\/b> native WordPress. This bug generates an exploit chain that starts from a\u2019<a href=\"https:\/\/www.fortinet.com\/it\/resources\/cyberglossary\/sql-injection\" target=\"_blank\" rel=\"noopener\">SQL injection<\/a> (SQLi) and culminates in a <b data-path-to-node=\"9\" data-index-in-node=\"191\"><a href=\"https:\/\/www.fortinet.com\/resources\/cyberglossary\/remote-code-execution\" target=\"_blank\" rel=\"noopener\">Remote Code Execution<\/a> (RCE) pre-auth<\/b>.<\/p>\n<p data-path-to-node=\"10\">Simply put:<\/p>\n<ul data-path-to-node=\"11\">\n<li>\n<p data-path-to-node=\"11,0,0\"><b data-path-to-node=\"11,0,0\" data-index-in-node=\"0\">No requirements:<\/b> The attacker does not need an account, secondary exploits, or special configurations.<\/p>\n<\/li>\n<li>\n<p data-path-to-node=\"11,1,0\"><b data-path-to-node=\"11,1,0\" data-index-in-node=\"0\">Zero interaction:<\/b> Simply having a WordPress site online and accessible is enough to be vulnerable.<\/p>\n<\/li>\n<li>\n<p data-path-to-node=\"11,2,0\"><b data-path-to-node=\"11,2,0\" data-index-in-node=\"0\">Standard target:<\/b> Even a clean, freshly launched WordPress installation, without any plugins, is at risk.<\/p>\n<\/li>\n<\/ul>\n<p data-path-to-node=\"12\">The flaws are officially tracked under two identifiers: <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-60137\" target=\"_blank\" rel=\"noopener\"><b data-path-to-node=\"12\" data-index-in-node=\"64\">CVE-2026-60137<\/b> <\/a>(SQL injection related) and <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-63030\" target=\"_blank\" rel=\"noopener\"><b data-path-to-node=\"12\" data-index-in-node=\"110\">CVE-2026-63030<\/b><\/a> (the actual RCE chain).<\/p>\n<h2 data-path-to-node=\"14\"><\/h2>\n<h2 data-path-to-node=\"14\">Impacted Versions and Security Releases<\/h2>\n<p data-path-to-node=\"15\">The specific technical details of the exploit have not yet been made public to avoid a massive wave of automated attacks (attacks <i data-path-to-node=\"15\" data-index-in-node=\"144\">zero day<\/i> on a large scale). However, we know for certain which branches of the software are involved:<\/p>\n<table data-path-to-node=\"16\">\n<thead>\n<tr>\n<td><strong>WordPress Branch<\/strong><\/td>\n<td><strong>Vulnerability Status<\/strong><\/td>\n<td><strong>Patched Version<\/strong><\/td>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><span data-path-to-node=\"16,1,0,0\"><b data-path-to-node=\"16,1,0,0\" data-index-in-node=\"0\">WordPress 7.0<\/b><\/span><\/td>\n<td><span data-path-to-node=\"16,1,1,0\">Vulnerable to SQLi and RCE<\/span><\/td>\n<td><span data-path-to-node=\"16,1,2,0\"><b data-path-to-node=\"16,1,2,0\" data-index-in-node=\"0\">7.0.2<\/b><\/span><\/td>\n<\/tr>\n<tr>\n<td><span data-path-to-node=\"16,2,0,0\"><b data-path-to-node=\"16,2,0,0\" data-index-in-node=\"0\">WordPress 6.9<\/b><\/span><\/td>\n<td><span data-path-to-node=\"16,2,1,0\">Vulnerable to SQLi and RCE<\/span><\/td>\n<td><span data-path-to-node=\"16,2,2,0\"><b data-path-to-node=\"16,2,2,0\" data-index-in-node=\"0\">6.9.5<\/b><\/span><\/td>\n<\/tr>\n<tr>\n<td><span data-path-to-node=\"16,3,0,0\"><b data-path-to-node=\"16,3,0,0\" data-index-in-node=\"0\">WordPress 6.8<\/b><\/span><\/td>\n<td><span data-path-to-node=\"16,3,1,0\">Vulnerable only to SQLi (CVE-2026-60137)<\/span><\/td>\n<td><span data-path-to-node=\"16,3,2,0\"><b data-path-to-node=\"16,3,2,0\" data-index-in-node=\"0\">6.8.6<\/b><\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<blockquote data-path-to-node=\"17\">\n<p data-path-to-node=\"17,0\"><b data-path-to-node=\"17,0\" data-index-in-node=\"0\">Security Note:<\/b> Given the extreme gravity of the situation, the official WordPress channels have started an extraordinary procedure <b data-path-to-node=\"17,0\" data-index-in-node=\"138\">forced automatic update<\/b> for all affected instances.<\/p>\n<\/blockquote>\n<h2 data-path-to-node=\"19\"><\/h2>\n<h2 data-path-to-node=\"19\">How to Check if Your Site is Safe and What to Do<\/h2>\n<p data-path-to-node=\"20\">If you run a business website or e-commerce site for your business, checking the status of your CMS immediately is your top priority.<\/p>\n<h3 data-path-to-node=\"21\">1. Check your WordPress version<\/h3>\n<p data-path-to-node=\"22\">Go to your site&#039;s dashboard and check that the version you are using is <b data-path-to-node=\"22\" data-index-in-node=\"71\">7.0.2, 6.9.5 or 6.8.6<\/b> (or later). If you notice that your site is stuck on a previous release, immediately perform a manual update from the section <i data-path-to-node=\"22\" data-index-in-node=\"226\">Noticeboard &gt; Updates<\/i>.<\/p>\n<h3 data-path-to-node=\"23\">2. Use the Free Scanner<\/h3>\n<p data-path-to-node=\"24\">The Searchlight Cyber team has made available a free scanning tool on <b data-path-to-node=\"24\" data-index-in-node=\"92\">wp2shell.com<\/b> to check in real time if your platform is still exposed to the vulnerability.<\/p>\n<h3 data-path-to-node=\"25\">3. Temporary Solutions (Workarounds)<\/h3>\n<p data-path-to-node=\"26\">If for technical or compatibility reasons you can&#039;t immediately update the WordPress core, experts recommend applying these emergency filters right away (knowing that they may limit some of your site&#039;s features):<\/p>\n<ul data-path-to-node=\"27\">\n<li>\n<p data-path-to-node=\"27,0,0\">Set up your own <b data-path-to-node=\"27,0,0\" data-index-in-node=\"23\">WAF<\/b> (Web Application Firewall) to block direct requests to endpoints <code data-path-to-node=\"27,0,0\" data-index-in-node=\"102\">\/wp-json\/batch\/v1<\/code> is <code data-path-to-node=\"27,0,0\" data-index-in-node=\"122\">?rest_route=\/batch\/v1<\/code>.<\/p>\n<\/li>\n<li>\n<p data-path-to-node=\"27,1,0\">Temporarily install a security plugin to prevent anonymous (unauthenticated) access to the REST APIs.<\/p>\n<\/li>\n<\/ul>\n<h2 data-path-to-node=\"29\"><\/h2>\n<h2 data-path-to-node=\"29\">The Digife Council<\/h2>\n<p data-path-to-node=\"30\">Faced with threats of this type <i data-path-to-node=\"30\" data-index-in-node=\"28\">zero-click<\/i> is <i data-path-to-node=\"30\" data-index-in-node=\"41\">pre-auth<\/i> Like wp2shell, temporary workarounds aren&#039;t enough: <b data-path-to-node=\"30\" data-index-in-node=\"102\">the\u2019<a href=\"https:\/\/www.digife.it\/en\/it-security\/\">only real defense<\/a> it&#039;s the immediate update<\/b>.<\/p>\n<p data-path-to-node=\"31\">We of <b data-path-to-node=\"31\" data-index-in-node=\"7\">Digife<\/b> We always remind our customers how vital it is to have a consistent technical maintenance plan. If you have concerns about your website&#039;s security, fear that forced updates may conflict with your existing plugins, or want a professional server audit, <a class=\"ng-star-inserted\" href=\"\/en\/contacts\/#contattaci\" target=\"_blank\" rel=\"noopener\" data-hveid=\"0\" data-ved=\"0CAAQ_4QMahgKEwi4vdqt1uCVAxUAAAAAHQAAAAAQjwI\">Contact our technical support team<\/a>. We&#039;ll secure your online business before it&#039;s too late.<\/p>","protected":false},"excerpt":{"rendered":"<p>Falla &#8220;wp2shell&#8221;: Oltre 500 Milioni di Siti WordPress a Rischio RCE Un fulmine a ciel sereno scuote il mondo del web design e della sicurezza informatica. \u00c8 stata appena identificata&#8230;<\/p>","protected":false},"author":4,"featured_media":36438,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-36437","post","type-post","status-publish","format-standard","has-post-thumbnail","category-curiosita-web"],"_links":{"self":[{"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/posts\/36437","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/comments?post=36437"}],"version-history":[{"count":1,"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/posts\/36437\/revisions"}],"predecessor-version":[{"id":36439,"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/posts\/36437\/revisions\/36439"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/media\/36438"}],"wp:attachment":[{"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/media?parent=36437"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/categories?post=36437"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.digife.it\/en\/wp-json\/wp\/v2\/tags?post=36437"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}