Cookie Consent by Free Privacy Policy Generator

Critical WordPress Vulnerabilities Under Active Exploitation

TechCrunch and Dark Reading report that two critical vulnerabilities in WordPress core software, CVE-2026-60137 and CVE-2026-63030, are being actively exploited just days after patches were released. The vulnerabilities allow attackers to chain together flaws to achieve remote code execution and complete site takeover. Security researchers estimate that tens of millions of WordPress sites remain vulnerable, with public proof-of-concept exploit code now widely available. Attackers are using the vulnerability chain to install backdoors, create rogue administrator accounts and deploy web shells for persistent access across compromised sites.

Why this matters for UK organisations

WordPress powers approximately 43% of all websites globally, including a significant proportion of UK business, public sector and e-commerce sites. The speed at which exploitation began following disclosure reflects how quickly attackers can weaponise publicly available vulnerability details and proof-of-concept code. For organisations running WordPress sites, this creates immediate operational risk: unpatched sites are now trivial to compromise, and attackers are actively scanning for vulnerable installations. The risk extends beyond the website itself to any backend systems, databases or customer data the site can access. Many UK organisations rely on WordPress for customer-facing services, content management, e-commerce platforms and internal portals, making this a material business risk rather than just a technical issue. The window between patch release and active exploitation has collapsed to days, not weeks, meaning that patching speed is now a critical operational capability.

What to review

Organisations should verify that all WordPress core installations, plugins and themes are fully patched and that a formal process exists to apply security updates within days of release, not weeks. Many organisations rely on managed WordPress hosting providers or agency partners to handle updates, so confirming who is responsible for patching and how quickly they act is essential. Where WordPress sites are self-hosted, IT teams should ensure that automated update mechanisms are enabled and tested, and that someone is monitoring for security advisories. For organisations with multiple WordPress sites, maintaining an inventory of all installations and their patch status is a practical governance step. Where sites have been compromised, incident response should include forensic investigation to understand what access was gained, what data may have been exposed, and whether backdoors or persistent access mechanisms remain in place. Reviewing web application firewall rules, access logs and administrator account activity can help identify signs of compromise.

Source: TechCrunch

News and blog posts
Today's brief focuses on three areas where trust in established security...
TechCrunch and Dark Reading report that two critical vulnerabilities in...
SecurityWeek reports that two zero-day vulnerabilities in SonicWall firewall...
Help Net Security reports that independent research by Milan Brož and...