Pakistan’s National Cyber Emergency Response Team (National CERT) has issued a high-severity cybersecurity advisory warning that attackers are actively exploiting critical vulnerabilities in WordPress Core that could allow complete takeover of affected websites without requiring user authentication.
According to the advisory, the primary vulnerability, CVE-2026-63030 (wp2shell), affects the WordPress REST API and can be combined with CVE-2026-60137, an SQL injection flaw in the WP_Query class, to gain full control of vulnerable websites.
National CERT said publicly available proof-of-concept exploit code has accelerated the threat, with real-world exploitation attempts detected within hours of the vulnerabilities being disclosed.
The two flaws have been assigned CVSS severity scores of 9.8 and 9.1, placing government websites, critical infrastructure, financial institutions, enterprises, and public hosting environments among the highest-risk targets. Vulnerable versions include WordPress Core 6.9.0 to 7.0.1, as well as 6.8.x and later for the affected components.
The agency warned that successful attacks could result in complete website compromise, unauthorized database access, theft of sensitive information, deployment of persistent web shells, service disruption, reputational damage, and further attacks on internal enterprise networks.
National CERT has advised organizations to immediately upgrade to patched WordPress versions, verify all public-facing installations, update plugins and themes, restrict unauthenticated access to vulnerable REST API endpoints, and deploy Web Application Firewalls (WAFs) where immediate patching is not feasible.
The advisory also recommends checking servers for unauthorized PHP files, rotating administrator credentials after patching, verifying the integrity of WordPress core files, continuously monitoring logs for suspicious activity, isolating potentially compromised systems, and reporting confirmed incidents through National CERT’s incident response framework. The agency said immediate patching remains the most effective defense against the ongoing attacks.





