Attackers are actively exploiting a pair of critical WordPress Core vulnerabilities — dubbed wp2shell — to install hidden backdoors on business websites without needing a login.
The exploit chain, tracked as CVE-2026-63030 and CVE-2026-60137, abuses the WordPress REST API’s batch-processing feature to achieve unauthenticated remote code execution. WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are affected. Patches (versions 6.9.5, 7.0.2, and 6.8.6) have been released and auto-updates pushed — but that’s where it gets tricky.
Why this matters here
WordPress powers a significant share of Australian business websites, from local trades to professional services firms. According to live tracking data, roughly one in five WordPress installations worldwide hasn’t applied the patch yet.
In our experience managing WordPress sites for Australian SMBs — from the Northern Beaches to Orange — the most common reason for missed patches is that a developer disabled auto-updates at some point to stop a custom theme from breaking. That’s exactly the kind of installation sitting exposed right now.
Researchers at Wiz and SANS have documented attackers installing PHP webshells disguised as plugins, creating rogue administrator accounts, and extracting database credentials. CISA added both CVEs to its Known Exploited Vulnerabilities catalogue on 21 July.
What to check
Confirm your WordPress version is 6.9.5 or 7.0.2 or later. Review your list of admin users for anything unfamiliar. Check the /wp-content/cache/ directory for unexpected PHP files. And if you haven’t looked at your plugin list recently, now would be the time.
If your website runs on WordPress and you’re not sure whether auto-updates are working, that’s a conversation worth having with whoever manages it. We work with businesses across Sydney, the Central West, and Brisbane to keep their WordPress sites patched and hardened — see our managed IT support and cybersecurity services.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
