Tracking Down Vulnerable WordPress Installations
Security Alert: The core WordPress framework is currently exposed to severe security flaws, officially tracked as CVE-2026-60137 and CVE-2026-63030. Collectively dubbed wp2shell, these vulnerabilities have been assigned a critical CVSS score of 9.8 out of 10, demanding immediate attention from network administrators.
Understanding the Target: What is WordPress?
WordPress is a globally dominant Content Management System (CMS). Originally engineered for blog publishing, it has evolved into a highly versatile platform capable of running virtually any type of website. Because it relies heavily on a massive ecosystem of plugins and themes, it is heavily deployed across enterprise networks—making it a highly lucrative target for cybercriminals.
The Threat Profile: What is the Impact?
The wp2shell vulnerabilities are exceptionally dangerous because they do not require attackers to possess valid login credentials. If exploited successfully, an unauthenticated, remote adversary can execute a devastating SQL injection attack. This intrusion pathway effectively grants the attacker full remote administrative privileges and the ability to execute arbitrary code (RCE) directly on the compromised WordPress server.
Remediation Strategy: Updates & Workarounds
To neutralize this threat, it is imperative that organizations patch their instances immediately. Please upgrade your WordPress environments to one of the following secure releases:
- Version 6.9.5 (or newer)
- Version 7.0.2 (or newer)
- Version 7.1 Beta 2 (or newer)
Hunting for Exposures with runZero
Gaining visibility into your attack surface is the first step in remediation. You can effortlessly locate all potentially vulnerable WordPress assets operating across your network by utilizing runZero.
Simply navigate to your Services Inventory and run the following search query to isolate the affected systems:
product:"wordpress" AND _service.product:wordpress
About runZero
runZero, a network discovery and asset inventory solution, was founded in 2018 by HD Moore, the creator of Metasploit. HD envisioned a modern active discovery solution that could find and identify everything on a network–without credentials. As a security researcher and penetration tester, he often employed benign ways to get information leaks and piece them together to build device profiles. Eventually, this work led him to leverage applied research and the discovery techniques developed for security and penetration testing to create runZero.
About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

