wp2shell Bypasses Password Always

Article by Nacata Security, 27/07/2026

Is your WordPress website exposed to the Internet right now?

There is an active exploit chain that is already installing webshells without a password.

The threat did not arrive alone: two chained vulnerabilities allow full server takeover without a username or password — something that would normally require prior access to the system.

And this is not theory: automated campaigns are actively detected right now, massively scanning vulnerable installations and deploying backdoors that survive even system reboots.

Metaphorical representation of the two chained vulnerabilities in the REST API: two digital pipes converging and opening a trapdoor toward remote code execution.
Active chained exploit

The attack requires no credentials — only a valid request.

The wp2shell chain links two critical vulnerabilities: CVE-2026-63030 and CVE-2026-60137. The first exploits a path confusion issue in the WordPress REST API batch processing endpoint. The second exploits an SQL injection in WP_Query via the author__not_in parameter. Together, they allow escalation from seemingly normal queries to full remote code execution, without the attacker ever having entered a password.

First they enumerate users, then they execute arbitrary code.

The attacks follow a clear pattern: first, mass scanning of exposed WordPress instances; then, REST API queries to enumerate administrators and collect usernames and email addresses. In parallel, local file inclusion attempts to read wp-config.php and steal database credentials. By the time the exploit lands, the server is already compromised before the administrator notices anything unusual.

Webshells hide by returning a fake 404 to go undetected for weeks.

Once inside, attackers establish persistence: PHP webshells in paths such as wp-content/cache, with random names that only respond when the correct parameter is included, returning a fake 404 to all other requests. In some cases, fraudulent administrator accounts are also created, or malicious plugins are installed to facilitate long-term remote control of the server.

Image of the automated mass scanning pattern: a fiber optic network representing millions of installations being detected and sequentially lit up by an automated pulse.
Automated mass scanning

This pattern is not exclusive to this campaign.

The combination of SQL injection and path confusion affects any web platform that processes batch requests without permission validation.

Automated exploits escalate within hours because mass scanners never rest or wait.

WordPress powers more than 40% of the world’s websites, exposing millions of installations to risk with every critical vulnerability.

The update already exists — so does the risk.

WordPress has released versions 7.0.2, 6.9.5, and 6.8.6 to close both vulnerabilities. But updating does not erase what has already happened: if your installation was exposed, you need to verify whether someone got in before you applied the patch.

Updating is not enough if they already got in.

Reviewing access logs for anomalous requests to the REST API is the real first step after updating. Next, inspect installed plugins and remove any recent additions without justification. This type of automated campaign operates within windows of hours, not days, meaning a vulnerable installation over a weekend may have been compromised before Monday.

New PHP files in wp-content are the clearest signal.

Look for recent PHP files in unusual locations within wp-content, especially in subdirectories such as cache or uploads. Also audit users with elevated permissions and remove any unauthorized accounts. If you find evidence of access to wp-config.php, rotate database credentials, authentication keys, and administration panel passwords immediately.

Metaphor for post-compromise persistence: a ghostly figure holding the server door open from the inside, representing the access that survives even after the patch has been applied.
Persistence after patching

If you confirm a compromise, the response must be completely decisive.

Containing the server, reinstalling from a verified clean backup, and rotating all secrets are the three steps that cut off real persistence. Patching over a compromised installation only seals the entry point while leaving the attacker inside.

Persistence survives the patch if you do not act.

Webshells with fake 404 responses are designed precisely for this: to go undetected for weeks while the attacker maintains access. Updating WordPress without cleaning the installation is like changing the lock without evicting the intruder already inside. A full cleanup is the only valid response when there is evidence of a real compromise.

Clean first, patch without further excuses.

The wp2shell chain demonstrates that poorly protected REST APIs are a potential backdoor. Do you know which version of WordPress your website is running right now?

Urgent steps to take now

  • Update to WordPress 7.0.2, 6.9.5, or 6.8.6 depending on your installed branch.
  • Review REST API logs and remove plugins without justification.
  • Look for new PHP files in wp-content and rotate credentials.

Do you know exactly which version of WordPress is protecting your website right now?

Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.

Related articles

Nacata Security, reach out to us anytime

How would you rate this news?

We are Nacata Security, get to know us

web: nacata.io

email: info@nacata.io

Phone: 919930793

LinkedIn: Nacata Security

Tools

New versions and features of tools used in offensive and defensive cybersecurity: scanners, exploitation frameworks, auditing software.

For those who want to stay up to date on which tools to use and what has improved.



RATING


7.1



Who are we?


At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.


We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.


We’d be glad to get in touch with you for whatever you need.