Hackers Exploit Patched WordPress Bugs – Millions of Sites Still at Risk

Researcher-discovered WP2Shell chain targets WordPress 6.8 through 7.0.1, leaving tens of millions of unpatched sites open to unauthenticated takeover

Al Landes Avatar
Al Landes Avatar

By

Image: Gadget Review

Key Takeaways

Key Takeaways

  • Chained REST API bugs grant unauthenticated attackers full remote control of WordPress sites.
  • WordPress 7.0.2 patches WP2Shell, but tens of millions of unpatched sites remain exposed.
  • Update immediately to 7.0.2 and re-enable automatic core updates to close the vulnerability.

Your WordPress site has zero plugins installed. Fresh deployment, bone-stock configuration. And it’s already vulnerable to full remote takeover — no login required. A chainable pair of bugs in the WordPress REST API, dubbed “WP2Shell,” lets attackers turn your site into their personal command line. WordPress 7.0.2 patches the flaws. The problem: tens of millions of sites haven’t updated yet, and automated exploit scanners are already sweeping the web like robocall bots that never sleep — the kind of computer problems that demand immediate action.

One Chain, Total Control

Two chained bugs in core WordPress grant unauthenticated attackers full site access on default installations.

Security researcher Adam Kues of Searchlight Cyber discovered the WP2Shell chain — two REST API vulnerabilities that, combined, deliver unauthenticated remote code execution. A separate SQL injection bug compounds the damage. Affected versions span WordPress 6.8 through 7.0.1 and the 7.1 beta, according to disclosure details reported by Searchlight Cyber and tracked by Patchstack.

Once inside, attackers can:

  • Upload web shells for persistent backdoor access
  • Create hidden admin accounts
  • Inject SEO spam or deploy phishing pages
  • Pivot into underlying server infrastructure

The exposure numbers illustrate the risk clearly. Less than half of WordPress installations typically run the latest version, according to independent sampling cited by Raidboxes. Roughly 15% of sites remain on vulnerable branches weeks after major patches — translating to tens of millions of exposed targets. Patchstack’s analysis identifies unauthenticated RCE and SQL injection bugs as the “most exploited WordPress vulnerabilities,” and prior plugin flaws with far smaller install bases triggered mass exploitation within days. A core bug touching hundreds of millions of installs is exponentially more attractive to threat actors — much like how hackers steal credentials by exploiting auth flaws the moment a patch window opens.

What You Do Right Now

Practical steps to close the door before automated scanners find your site.

If you manage a WordPress site, update to 7.0.2 immediately through Dashboard → Updates. Re-enable automatic core updates if you’ve turned them off — that single setting is the behavioral gap driving most of this exposure. You know that dismiss-three-times-then-deal-with-consequences approach to software updates? This isn’t the time for it. Beyond the update itself, deploying or verifying a web application firewall through your host, Cloudflare, or a security plugin adds a critical layer of protection even before patches reach every install. Monitor REST API logs for unusual activity and unexpected admin accounts appearing without explanation.

WordPress’s auto-update strategy works — but only when you stop fighting it. The platform isn’t broken. The patching habits are. For site owners who won’t update manually, managed WordPress hosting is increasingly where this market heads. Your call whether you get there before or after the breach.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →