Hackers are widely exploiting two vulnerabilities in WordPress.
If you have a WordPress website, the message this week is clear: update it immediately. Two vulnerabilities in the software are actively being exploited online. WordPress is the foundation for over half of all websites, meaning the potential impact is vast. Security experts report that the attacks commenced just hours after the patches were released. An AI model is involved in both sides of the equation.
What wp2shell is
WordPress released patches for versions 7.0.2 and 6.9.5 last Friday and initiated forced auto-updates due to the associated risks. Researchers have named the vulnerability wp2shell. This flaw consists of two bugs; one is a SQL injection issue and the other, labeled critical with a score of 9.8 out of 10 by TechRadar, is a route confusion bug in the REST API that allows requests to bypass authentication. While each bug is complex individually, when combined, they grant an anonymous attacker full remote control.
The đź’ś of EU tech
Get the latest insights from the EU tech landscape, a piece from our seasoned founder Boris, and some dubious AI-generated art. Subscribe for free to receive it every week in your inbox!
“The attack has no prerequisites,” noted Searchlight Cyber’s researcher Adam Kues, who discovered and reported it. It functions on a standard WordPress installation without any plugins.
AI's role in discovery and exploitation
This is where the situation becomes concerning for cybersecurity experts. Kues didn’t uncover the exploit chain manually; he utilized OpenAI’s GPT-5.6 over roughly 10 hours, work that his firm estimates could be worth $500,000 to exploit brokers. Conversely, these same tools are also being misused. “Reproducing them with the aid of advanced AI models was merely a matter of time and resources,” stated watchTowr researcher Jake Knott to The Register. His team managed to replicate the critical bug in mere minutes.
Benjamin Harris, the founder of watchTowr, clearly described this trend to SecurityWeek. He noted that proof-of-concept exploits appeared within hours instead of the previous day-long timeframe. “The gap between public disclosure and exploitation has significantly narrowed.”
What attackers are doing
By early Saturday, the exploitation had begun in earnest. Initial public exploit code aimed at stealing hashed passwords was released, followed by remote code execution as further details emerged. watchTowr documented tens of thousands of attempts and over 100 backdoor admin accounts created by various groups. VulnCheck confirmed more than two dozen distinct exploits by Sunday.
Once they gain access, attackers install fake plugins, steal credentials, and bring in additional tools. In one instance, watchTowr observed a group attempting to deploy Overlord RAT, a remote-access trojan. Another payload embedded a web shell within a fake security plugin.
How many sites are at risk
There is no exact figure available. Over 400 million sites are running the versions affected, though many have already applied patches. Consultant Daniel Card told TechCrunch that in his sampling of approximately 3,500 sites, the vulnerable share was under 15%, equating to nearly 90 million. Data from Wiz, now owned by Google, conveyed a similar message to The Hacker News, revealing that 60% of organizations operating WordPress had at least one exposed instance when the vulnerabilities were disclosed. A quarter had a vulnerable server exposed to the internet.
The impact was mitigated by pre-existing defenses. WordPress implemented forced auto-updates, Cloudflare intercepted attacks at its firewall, and Automattic stated that its hosted sites were safeguarded even before the patches were released.
The larger warning
The risk remains significant for those who delayed action. Matt Mullenweg, co-founder of WordPress, described it as a kind of pre-authentication takeover rarely seen in the software’s 23-year history, adding to a series of recent WordPress security incidents. Knott’s recommendation is more severe; he stated that any site that postponed patching until Monday is likely already compromised, urging checks for unauthorized admin accounts even after updates. This reflects the reality that AI-driven security advancements now operate at machine speed, following an AI incident involving Hugging Face. Defenders must stay vigilant.
Other articles
Hackers are widely exploiting two vulnerabilities in WordPress.
Two fixed vulnerabilities in WordPress, known as wp2shell, are currently facing widespread attacks. AI played a role in identifying the issue and exploiting it. Millions of websites could be at risk.
