Pakistan’s National Cyber Emergency Response Team (National CERT) has issued a critical cybersecurity advisory warning that hackers are actively exploiting severe vulnerabilities in WordPress Core that could allow attackers to take complete control of websites without requiring any login credentials.
According to the advisory, the primary vulnerability, CVE-2026-63030 (wp2shell), affects the WordPress REST API and can be chained with CVE-2026-60137, an SQL injection flaw in the WP_Query class, to compromise vulnerable websites. National CERT said proof-of-concept exploit code is already publicly available, and exploitation attempts were detected within hours of the vulnerabilities being disclosed.
The agency assigned the vulnerabilities CVSS severity scores of 9.8 and 9.1, warning that government portals, critical infrastructure, financial institutions, enterprise websites, and public hosting environments using vulnerable WordPress versions are among the most at-risk systems. Affected versions include WordPress Core 6.9.0 through 7.0.1 and 6.8.x and later, depending on the specific vulnerability.
National CERT warned that successful attacks could result in complete website compromise, unauthorized SQL injection, theft of sensitive data, installation of persistent web shells, disruption of online services, reputational damage, and attackers using compromised servers to move laterally across enterprise networks.
To reduce the risk, the advisory urged organizations to immediately update WordPress Core to the latest patched versions, verify installed versions across all public-facing websites, update plugins and themes, restrict unauthenticated access to vulnerable REST API routes, and deploy Web Application Firewalls where immediate patching is not possible.
The advisory also recommended inspecting servers for unauthorized PHP files, rotating administrator credentials after applying patches, conducting integrity checks of WordPress core files, continuously monitoring server logs for suspicious activity, isolating potentially compromised systems, and reporting confirmed incidents through National CERT’s incident reporting mechanism.
The agency stressed that immediate patching and continuous monitoring are essential to protect public-facing digital infrastructure from ongoing cyberattacks.
Get the latest tech news, telecom insights, and product launches wherever you prefer.
Add ProPakistani to Preferred Sources and see more of our stories in Google Search and Top Stories.