ISLAMABAD: A high-severity cybersecurity alert from Pakistan’s National Cyber Emergency Response Team (National CERT) warns that hackers are exploiting vulnerabilities in the WordPress core, which could enable them to gain complete control over compromised sites without requiring user authentication.
As per the advisory, the vulnerability identified as CVE-2026-63030 (wp2shell) and the SQL injection vulnerability in the WP_Query class (CVE-2026-60137) enable attackers to take complete control of websites using the WordPress REST API via remote code execution.
The advisory says that websites running WordPress versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 are vulnerable.
Website administrators have been advised to upgrade their sites to the latest patched version to address this issue since public exploit code is available and active exploitation has been seen.
National CERT also suggests that website owners check whether the security updates have been successfully implemented or not and enable automatic updates whenever possible.

