"WP2Shell": 2 WordPress Bugs Just Cracked Open Tens of Millions of Sites

:shield: “WP2Shell”: Two WordPress Bugs Just Handed Hackers the Keys to Tens of Millions of Sites

They patched it last week. Attackers were mass-owning sites 3 days later. If your site runs WordPress, keep reading — this one’s ugly.

2 bugs chained = full remote takeover. No password needed. WordPress runs ~40% of the entire web.

Affected: WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1. Attackers are dropping backdoors, making fake admin accounts, and planting hidden control panels. The full TechCrunch writeup is here.

Everything on fire

Right, so here’s what’s actually happening under the hood. Someone found two separate holes in WordPress itself — not a dodgy plugin, the actual core software that runs almost half the internet — and figured out that if you use them together, you can walk straight into a website with no login. Zero. Nada. They named the trick WP2Shell. Cute name. Absolute nightmare if it’s your site.

🧩 Dumb Mode Dictionary (read this first, no shame)
Nerd Word What It Actually Means
WordPress The free software that runs ~40% of all websites (blogs, shops, your cousin’s bakery site).
RCE (Remote Code Execution) The scary one. A stranger on the internet gets to run their own commands on your site. Game over.
SQL injection Tricking a website’s database into coughing up data or obeying the attacker by typing sneaky text into a box.
Pre-auth / unauthenticated No username, no password needed. Anyone can do it. This is the worst kind.
Web shell / backdoor A hidden secret door the hacker installs so they can come back anytime, even after you “fix” things.
CVE The official ID number a bug gets, like a license plate. Here: CVE-2026-60137 + CVE-2026-63030.
📰 What broke, in plain English
  • Two bugs in WordPress core. On their own, annoying. Chained together, catastrophic.
  • Bug one (CVE-2026-60137) lets an attacker sneak commands into the site’s database.
  • Bug two lets them turn that into running their own code on your server.
  • Result: they own the whole site. Content, customer data, everything.
  • WordPress pushed an emergency patch and basically screamed “UPDATE NOW.” The Register has the gory details.
⏱️ The timeline (this is the part that'll ruin your weekend)
  • July 17 — Patch drops. Official advisory published.
  • ~July 20 — Someone posts a working exploit publicly. And the internet catches fire.
  • Within 3 days — mass scanning. Bots crawling the whole web looking for un-patched sites to hit.
  • Now — attackers installing backdoors, creating rogue admin accounts, and dropping web shells for permanent access.

Kids these days think “I’ll patch it this weekend” is a plan. It is not a plan. The gap between “patch exists” and “everyone’s getting hit” is now measured in hours, not months.

🔧 What to do RIGHT NOW if you run a WordPress site (5-minute version)
  1. Log in and update WordPress to the latest version. If you’re on 6.9.0–6.9.4 or 7.0.0–7.0.1, you’re a target. Do it now, not after coffee.
  2. Check for admin users you don’t recognize. Users → All Users. See a weird admin? You may already be owned.
  3. Install a free scanner like Wordfence or MalCare and run a full malware scan.
  4. If you find a backdoor, updating alone won’t save you — the hidden door stays. You need a proper cleanup (more on that below).
  5. Turn on auto-updates so future-you doesn’t get burned at 3 AM again.
😤 Why this keeps happening (the honest take)

It’s WordPress core. Not some sketchy plugin from 2014. The thing everyone trusts.

That’s the whole problem — one bug in software that runs 40% of the web is basically a skeleton key to a huge chunk of the internet. Attackers don’t need to be clever anymore. Someone smart finds the hole, posts the recipe, and then a thousand script-kiddies with automated bots do the actual damage while the rest of us sleep.

The fix has existed for weeks. The sites getting hit are the ones nobody’s babysitting. Which, let’s be real, is most of them.

Cool. Half the internet is one click from getting owned… Now What the Hell Do We Do? (ง •̀_•́)ง

Cleaning up a mess

Here’s the thing about a mass panic: while everyone’s scared, the people who calmly show up with a fix get paid. Millions of small-business owners have no idea their site is a sitting duck. That’s not a tragedy — that’s a to-do list. Five plays, honestly told.

📡 The Version Leak Radar

Most WordPress sites announce their own version number right in the page code (it’s called a “generator” tag, and there’s a file called readme.html that basically shouts it). So you can tell from the outside which sites are still running the vulnerable version — without touching anything illegal. Pick a niche (dentists, plumbers, gyms in one city), scan public homepages, build a list of the exposed ones, then send a polite “hey, your site’s exposed, I can fix it today for $X” email.

:brain: Example: A 24-year-old freelancer in Portugal uses the free WPScan and Wappalyzer browser extension to check 200 local restaurant sites, finds 38 running old WordPress, cold-emails all 38, lands 6 emergency jobs at €180 each = ~€1,080 in a weekend.

:chart_increasing: Timeline: First paying client in 2–4 days. This dries up in ~4–6 weeks as sites auto-update or get hit and taken offline. Move fast.

🧹 The Backdoor Exterminator

Thousands of sites already got a web shell installed. Here’s the cruel twist: updating WordPress does NOT remove the hacker’s hidden door. Owners will update, think they’re safe, and get re-owned. You become the person who does the deep clean — remove backdoors, kill rogue admins, harden the site so it doesn’t happen again.

:brain: Example: A self-taught guy in the Philippines offers “hacked WordPress recovery” gigs, uses free Wordfence + Sucuri’s free scanner to find and remove backdoors, charges $120–$250 per cleanup, does 3 a week via a simple Facebook page = ~$500/week.

:chart_increasing: Timeline: Steady work for 2–3 months as the compromise wave plays out. Reputation compounds — one saved site = referrals. This is the longest-lasting play here.

📖 The WP2Shell Rosetta Stone

When a scary new bug gets a scary new name, nobody has written the plain-English version yet. Panicked site owners are Googling “WP2Shell what do I do” and finding only dense security-firm jargon. Be the first clean, simple, step-by-step “am I affected and how do I fix it” guide. First-mover on the search results becomes the go-to link everyone shares.

:brain: Example: A blogger in India publishes a dead-simple “WP2Shell Fix Guide (No Tech Skills Needed)” the same week, links free tools and hosting affiliate offers, rides the search traffic spike to ~15,000 visitors in month one and a few hundred bucks in affiliate + a wave of DMs asking her to just fix it for them.

:chart_increasing: Timeline: Traffic peaks in the first 3 weeks while the news is hot, then tapers but keeps a long tail as people discover hacked sites months later.

🪟 The Patch Window Sprint

Small businesses with a website and zero tech person are the sweet spot — they literally cannot patch themselves and don’t know they need to. Offer a flat “emergency patch + hardening + auto-update setup” package. You’re not selling fear, you’re selling one hour of peace of mind. Bundle 10-15 clients on a small monthly “we keep you patched” retainer and you’ve got recurring income.

:brain: Example: A student in Kenya DMs local shops on Instagram offering a one-time “site lockdown” for $60 plus $15/month monitoring, uses free managed-update tools like ManageWP to watch 20 sites from one dashboard = ~$300/month recurring after a month of hustling.

:chart_increasing: Timeline: First clients within a week. The recurring retainer is the win — it outlives this specific bug because there’s always another WordPress bug next month. (There always is.)

🕳️ The Honeypot Signal Trap

Grey-hat-flavored but fully legal: set up a deliberately fake, isolated WordPress site (a “honeypot”) on cheap hosting and watch which attacker addresses and payloads come knocking. Package those “here’s who’s attacking and how” indicators into a simple threat feed or a public writeup. Security teams, hosting companies, and bug-bounty circles genuinely pay for or reward fresh attack data.

:brain: Example: A cybersecurity hobbyist in Brazil spins up a honeypot with the free T-Pot toolkit on a $5/month server, catches live WP2Shell attempts within hours, writes it up, and turns the reputation into paid threat-intel consulting + a following that leads to a $2k contract.

:chart_increasing: Timeline: First juicy data in 24–48 hours (this bug is being scanned constantly right now). The clout and connections last way longer than the bug itself.

🛠️ Follow-Up Actions
Goal Do This Free Tool
:magnifying_glass_tilted_left: Check if you’re vulnerable Scan your own site WPScan
:broom: Find hidden backdoors Deep malware scan Sucuri SiteCheck
:shield: Block future attacks Install a firewall plugin Wordfence
:satellite_antenna: Watch many sites at once Central dashboard ManageWP
:hole: Catch live attackers Run a honeypot T-Pot

:high_voltage: Quick Hits

If You Want To… Do This
:police_car_light: Not get hacked tonight Update WordPress right now — 6.9.5 / 7.0.2 or newer
:money_bag: Make money this week Scan local business sites, offer emergency fixes
:brain: Understand the bug Read Rapid7’s breakdown
:broom: Clean an owned site Run Wordfence, then rebuild
:open_book: Track the exploitation Follow The Hacker News coverage

The patch has been out for weeks. The only sites getting owned are the ones nobody’s watching. Don’t be the 3 AM phone call.

1 Like