CybersecurityJuly 19, 2026· via Security Affairs

WordPress flaw exposes 500M sites to instant takeover

WordPress flaw exposes 500M sites to instant takeover

Image : Security Affairs

WordPress administrators have less than a week to update their sites after researchers released public exploits for two critical flaws that can be chained to take over any default installation without credentials.

The vulnerabilities—CVE-2026-63030 and CVE-2026-60137—affect the REST API batch route and the WP_Query author__not_in parameter respectively, enabling pre-authentication remote code execution on WordPress 6.9.x and 7.0.x. Because the flaws require no user interaction or valid accounts, attackers can weaponize them in minutes, making this one of the most dangerous WordPress security events in years.

A patch is already waiting—and it installs itself

WordPress has shipped 7.0.2 and 6.9.5 to close both security gaps and, unusually, enabled forced automatic updates for sites still on vulnerable versions. The move underscores the severity: even sites with no plugins installed are at risk. Administrators who cannot patch immediately can temporarily block access to the vulnerable REST API endpoints via WAF rules or security plugins, but the team stresses these are stopgaps that may break legitimate functionality.

A near-zero barrier to mass compromise

Searchlight Cyber, which discovered the flaws, also released an online checker (wp2shell.com) so owners can confirm exposure without waiting for external scans. With an estimated 500 million sites running WordPress, the potential for widespread attacks is considerable. The researchers withheld technical details for days to give defenders a head start, but once proof-of-concept code was released, the window for exploitation narrowed dramatically.

Why it matters

This is not a niche plugin bug—it is a core WordPress vulnerability that opens the entire ecosystem to trivial, credential-free takeover. The forced auto-updates show how seriously WordPress treats the risk, yet many sites still run outdated versions. Site owners who delay patching risk not only defacement or data theft, but also being co-opted into botnets or phishing campaigns. The release of public exploits means active scanning has already begun; updating to 7.0.2 or 6.9.5 is no longer optional.


Source: Security Affairs. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on Security Affairs →

← Back to home