Searchlight Cyber disclosed the wp2shell chain (CVE-2026-63030 + CVE-2026-60137) on 17 July 2026, unauthenticated RCE against WordPress core. Emergency releases 6.9.5 and 7.0.2 shipped the same day; CISA added both CVEs to KEV under BOD 26-04. A six-point managed website maintenance playbook: inventory, assume-breach hunt, WAF, REST hardening, tested backups, 24/7 named ownership.
wp2shell is the name Searchlight Cyber assigned to a chain combining CVE-2026-63030, an interpretation-conflict bug in the batch processor of the WordPress REST API endpoint /wp-json/batch/v1, with CVE-2026-60137, a SQL injection in the same request path. Chained, the two vulnerabilities yield unauthenticated remote code execution on a default WordPress installation. Searchlight Cyber published technical details on 17 July 2026, and mass-scanning plus in-the-wild exploitation was documented across the following 96 hours by Wiz, Rapid7, BleepingComputer, SecurityWeek and The Hacker News. Public proof-of-concept exploits were available within hours of disclosure.
The vulnerable branches are WordPress 6.9.0 through 6.9.4 and WordPress 7.0.0 through 7.0.1. On 17 July 2026, WordPress.org shipped emergency releases 6.9.5 and 7.0.2 and propagated them through the platform's forced auto-update channel. Any installation on 6.9.5 or higher on the 6.9.x branch or 7.0.2 or higher on the 7.0.x branch has the vulnerable code path closed. Older WordPress branches that are no longer receiving security backports should be upgraded to a supported branch on the same maintenance window.
On 21 July 2026, the US Cybersecurity and Infrastructure Security Agency added both CVE-2026-63030 and CVE-2026-60137 to its Known Exploited Vulnerabilities catalogue and issued Binding Operational Directive 26-04, setting federal remediation deadlines of 24 July and 4 August 2026. The KEV listing is the compliance signal that mass exploitation is verified and that the vulnerabilities are being weaponised against production systems, not merely proof-of-concept material. For non-federal operators, KEV plus BOD 26-04 is the standard cyber-insurance and audit trigger to treat the remediation clock as measured in days rather than weeks.
Because the auto-update closes the vulnerable code path but does not remediate persistence installed by an attacker who exploited the vulnerability before the update landed. Public reporting from Wiz, Rapid7, BleepingComputer, SecurityWeek and The Hacker News across the four days after disclosure documented four persistence patterns on wp2shell-compromised sites: PHP webshells dropped into wp-content/uploads, themes and plugins folders; malicious plugins installed and activated through compromised admin sessions; backdoor administrator accounts created directly against the database; and exfiltration of the wp_users table including password hashes and session tokens. A patched site can still be fully controlled by the attacker through any of these artefacts, which is why assume-breach hunting is mandatory after the auto-update.
One, maintain a living inventory of every WordPress property with core and plugin versions, hosting owner and operational owner, and verify auto-update actually applied 6.9.5 or 7.0.2 on every asset. Two, run an assume-breach threat hunt covering PHP webshells in uploads, themes and plugins; unknown or recently-updated plugins; administrator accounts created in the exposure window; anomalous outbound connections; and POST volume signatures to /wp-json/batch/v1. Three, put every public WordPress site behind a WAF with wp2shell rule packs from Cloudflare, Wordfence or Sucuri. Four, harden the REST and XML-RPC surface, enforce 2FA on all administrator and editor accounts, and rotate credentials after the hunt. Five, run a quarterly restore drill and record actual restore time. Six, contract 24/7 managed website maintenance with a named operational owner.
PHP files with recent timestamps in wp-content/uploads, wp-content/themes and wp-content/plugins that do not match the plugin or theme's official release; installed plugins not present on the last known-good manifest, or that shipped an update inside the exposure window from an unfamiliar author; administrator accounts in wp_users with the administrator capability in wp_usermeta created inside the exposure window, and any recent password change the business owner did not authorise; anomalous outbound connections from the web-server host to cloud storage, code hosting and paste-site infrastructure; access logs showing the response-code and body-size signatures Searchlight Cyber published for wp2shell exploitation; and PHP error logs for suspicious child processes of the web server. The hunt output is a signed artefact that goes into the site's incident file whether or not it finds anything.
Call IT Dev operates software development, cybersecurity and technical support engagements from Morocco with nearshore EU-time-zone coverage, delivery in English, French, Spanish and Arabic, and a regulatory posture aligned with CNDP Law 09-08 and GDPR obligations. The engagement applies the six-point playbook end-to-end on a WordPress estate: living inventory reconciled to weekly ASM sweeps, assume-breach hunting on core CVEs with wp2shell-specific content, WAF integration and virtual patching across hosting providers, REST and XML-RPC hardening plus 2FA enforcement, quarterly tested restore drills, and 24/7 managed website maintenance with a named operational owner and a documented incident-response runbook.
CALL IT DEV — Software, AI and dedicated tech teams — Casablanca | Madrid | Dubai — contact@callitdev.com — +212-537-373777