Active Exploitation Alert: Critical WordPress Core and Bricks Builder Vulnerabilities Enable Unauthenticated Remote Code Execution (RCE)

Active Exploitation Alert: Critical WordPress Core and Bricks Builder Vulnerabilities Enable Unauthenticated Remote Code Execution (RCE)

Executive Summary

A critical vulnerability chain, known as wp2shell, has been identified in WordPress Core and select plugins, enabling unauthenticated remote code execution (RCE) on default WordPress installations. This flaw, which requires neither plugins nor authentication, is being actively exploited in the wild. Public proof-of-concept exploits are widely available, and mass exploitation has been observed. The United States Cybersecurity and Infrastructure Security Agency (CISA) has confirmed active exploitation of this vulnerability, underscoring the urgent need for immediate remediation by all WordPress administrators.

Technical Information

The wp2shell attack chain leverages multiple vulnerabilities in WordPress Core and the Bricks Builder plugin. The primary vulnerabilities are CVE-2026-63030 (REST API batch-route confusion), CVE-2026-60137 (SQL injection in the author__not_in parameter of WP_Query), and CVE-2024-25600 (Bricks Builder plugin RCE).

CVE-2026-63030 introduces a logic flaw in the REST API batch endpoint, allowing attackers to bypass authentication and input validation. This enables the chaining of further attacks, such as CVE-2026-60137, which is a SQL injection vulnerability in the author__not_in parameter. By exploiting this, attackers can extract sensitive data, including password hashes, from the database. When combined, these flaws allow for the upload and execution of arbitrary PHP code, resulting in full server compromise.

The Bricks Builder plugin vulnerability (CVE-2024-25600) allows unauthenticated attackers to inject and execute PHP code due to improper input handling. This can lead to complete site takeover, data exfiltration, and the deployment of malware.

The attack chain is particularly dangerous because it affects default WordPress installations, does not require authentication, and can be exploited remotely. The presence of public proof-of-concept code and automated exploitation tools has led to widespread attacks, with threat actors targeting vulnerable sites at scale.

Exploitation in the Wild

Active exploitation of these vulnerabilities has been confirmed by multiple security research organizations and media outlets. CISA added CVE-2026-63030 to its Known Exploited Vulnerabilities (KEV) catalog on July 21, 2026, confirming that exploitation is ongoing and remediation is mandatory for federal agencies. Security firms such as watchTowr, BleepingComputer, and F5 Labs have reported real-world attacks, including password hash extraction, unauthorized plugin uploads, and direct RCE. Mass exploitation attempts have been observed on social media platforms and security forums, with attackers leveraging automated tools to compromise large numbers of WordPress sites.

APT Groups using this vulnerability

At the time of writing, there is no public attribution of this vulnerability chain to specific Advanced Persistent Threat (APT) groups. However, the scale, automation, and sophistication of the attacks suggest involvement by organized cybercriminal groups and botnets. No evidence has been found of targeting by nation-state actors or sector-specific campaigns, but the situation may evolve as more intelligence becomes available.

Affected Product Versions

The following versions are confirmed to be affected:

WordPress Core versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1 are vulnerable to the full RCE chain involving both CVE-2026-63030 and CVE-2026-60137. Versions 6.8.0 through 6.8.5 are vulnerable to the SQL injection (CVE-2026-60137) but cannot be chained to RCE without the REST API bug. All versions of the Bricks Builder plugin up to and including 1.9.6 are affected by CVE-2024-25600.

The vulnerabilities have been addressed in WordPress Core versions 6.8.6, 6.9.5, 7.0.2, and 7.1 Beta 2, and in Bricks Builder version 1.9.7 and above.

Workaround and Mitigation

Immediate patching is the most effective mitigation. Administrators should upgrade WordPress Core to at least 6.8.6, 6.9.5, or 7.0.2, and Bricks Builder to 1.9.7 or later. As a temporary control, block access to /wp-json/batch/v1 and URLs containing ?rest_route=/batch/v1 at the web server or Web Application Firewall (WAF) level. Monitor server logs for suspicious activity, particularly requests matching the above patterns and unauthorized plugin uploads. Scan for unfamiliar PHP files in /wp-content/uploads/ and plugin directories, as these may indicate webshell deployment. Utilize the wp2shell.com vulnerability scanner to assess site exposure. Cloudflare has deployed WAF protections for these vulnerabilities across all plans, providing an additional layer of defense.

Indicators of Compromise

The following table contains real-world indicators of compromise (IOCs) extracted from public sources. These indicators are point-in-time and should be validated before enforcement in your environment.

Type

Indicator

Reported (date)

Source

 

Domain

wp2shell[.]com

2026-07-18

BleepingComputer

No additional public indicators were available at the time of writing.

References

Rescana is here for you

Rescana empowers organizations to manage third-party risk and supply chain security with our advanced TPRM platform, providing continuous monitoring, automated risk assessment, and actionable intelligence. We are committed to helping you stay ahead of emerging threats and maintain a resilient security posture. For any questions or further assistance, please contact us at info@rescana.com.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.