The Wire
TechnologyCybersecurityWorld

Hackers are exploiting patched WordPress flaws, agencies warn

Researchers say two patched WordPress flaws are already being actively exploited.

Why it matters: WordPress runs a huge share of the web, so the exposure affects publishers, businesses and site operators broadly. It also shows how fast attackers can move after a patch lands.

  • WordPress released fixes on July 17, 2026 for two vulnerabilities affecting 6.9.x and 7.0.x.
  • New Zealand's National Cyber Security Centre said on July 20 the flaws were under active exploitation.
  • The issues can be chained to reach remote code execution on unauthenticated targets, according to the advisory.
  • WordPress said it enabled forced automatic updates for affected installations because of the severity.

WordPress shipped security updates on July 17, 2026 for two flaws in its core software, then warned that affected installs would receive forced automatic updates because of the severity of the issues. The release notes say one bug is a facilitated SQL injection flaw and the other is a REST API batch-route confusion issue that can lead to remote code execution when chained. WordPress release notes

By July 20, New Zealand's National Cyber Security Centre said the two vulnerabilities were under active exploitation and warned that an unauthenticated attacker could chain them to reach remote code execution. The NCSC described the situation plainly: "Two vulnerabilities affecting WordPress are under active exploitation." NCSC advisory

NIST's NVD entry for CVE-2026-63030 says WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 are affected, and that the route-confusion flaw combined with CVE-2026-60137 could allow SQL injection and remote code execution. WordPress's release notes say the 7.0.2 security release addresses one critical and one high severity issue. NVD entry WordPress release notes

Secondary reporting said public exploits had already been released for the exploit chain, which it called wp2shell. BleepingComputer also cited Searchlight Cyber estimating WordPress powers more than 500 million websites. Cloudflare said it deployed WAF protections for both vulnerabilities across plans, including free accounts proxied behind its platform. BleepingComputer Cloudflare advisory

By the numbers

  • July 17, 2026 - WordPress released the fixes
  • July 20, 2026 - New Zealand's NCSC said the flaws were under active exploitation
  • 500 million+ websites - Searchlight Cyber estimate cited by BleepingComputer

Yes, but: The exact scale of exploitation is not quantified in the official advisories reviewed, so claims of activity at scale come from secondary reporting.

What's next: Operators should confirm they are on fixed versions 6.9.5, 6.8.6 or 7.0.2 and check whether forced auto-updates applied.

Based on reporting from

  • TechCrunch

See how this story touches your network - open The Wire in Jane.

Open in Jane