Only $25 capital and AI, WP2Shell WordPress Vulnerability Threatens Millions of Websites Without Login!

The world of global cybersecurity is again shaken by spectacular and gruesome findings. a high-level security vulnerability chainCRITICAL ZERO-DAY) has just been discovered on the core system (Core) WordPress. named gap WP2Shell This allows the hacker to take full control of a website anonymously without the need for logging in, without the interaction of the site owner, and without relying on any third-party plugin.

Interestingly, based on the latest security research report from the Searchlight Cyber team, the creation of this high-screen complex exploit did not take months by the elite hacker team. This exploitation was successfully designed in just 10 hours with the help of the latest generative AI model (GPT-5.6 Sol Ultra) and only cost API tokens of 25 US dollars (approximately IDR 400 thousand).

WP2Shell Technical Anatomy: Combination of Two Deadly Slits in WordPress Core

As adapted from the in-depth analysis of CyberNews and cyber-threatening intelligence documents, attacks wp2shell wordpress vulnerability It works by combining two major security vulnerabilities in WordPress’s default library code (WordPress Core):

  • CVE-2026-63030 (REST API Batch-Route Confusion): the route confusion gap at the end point (Endpoint) Batch Rest API has been in existence since the Rest architecture update. This vulnerability permits an anonymous HTTP request bypassing the access rights check mechanism (Authentication bypass).
  • CVE-2026-60137 (SQL Injection on WP_Query): imperfect data sanitation bug on internal functions wp_query, especially when processing parameters author__not_in. This gap allows the hacker to insert a malicious SQL query directly into the database.

When these two slits are coupled in a single wave of attacks, the hacker can execute remote code commands (Remote Code Execution / RCE) on the server that accommodates the WordPress site. Security researchers note that this exploit chain exploits internal memory processing logic such as Oembed Cache Rows, Changeset Theme customization, to cycle handling Post-parent To inject malicious code instantly.

The Role of Artificial Intelligence: Cyber Exploitation Quantum Jump

As explained by security researcher Adam Kues from Searchlight Cyber, the discovery of this gap chain is a clear testament to how artificial intelligence technology changes landscapes Cybersecurity drastically. on the black market (Dark Web), the RCE exploitation chain on the unpatched WordPress core system is usually priced up to $500,000 (approximately IDR 8 billion).

However, by utilizing sophisticated AI models to analyze code logs and designing complex payloads, the process that previously took weeks can now be completed in just a matter of hours. “Without the help of AI, it is almost impossible for any security researcher to be able to complete the RCE exploit chain in this complex in just 10 hours,” said Kues in his research notes.

“Once the vulnerability details are published, reproducing exploits with the help of front-line AI models is only a matter of time and token availability.” write the research.

Real Impact on the Field: Waves of Mass Hacking and Magical Backdoor

Adapted from cyber traffic monitoring by Kevintel and Watchtowr, exploits wp2shell wordpress vulnerability has now expanded aggressively on the internet. Cyber criminals use automation scripts to scan millions of WordPress domains around the world massively.

Reports from researchers in the field confirm that hackers have successfully infiltrated thousands of sites and created more than 100 stealth administrator accounts (Backdoor Admin Accounts). After successfully logging in, the culprit installs a fake plugin and injects the data picker malware (Information Stealer) such as StealC to steal user credentials, transaction data, and sensitive databases.

Affected version of WordPress:

  • WordPress version 6.9.0 to 6.9.4: Affected by the WP2Shell RCCE chain.
  • WordPress version 7.0.0 to 7.0.1: Affected by the WP2Shell RCCE chain.
  • WordPress version 6.8.0 to 6.8.5: Only affected by the SQL Injection bug (CVE-2026-60137).

Quick Rescue Steps for Webmasters and Site Owners

Based on official instructions from the WordPress security team and global cyber experts, all WordPress-based website managers are advised to immediately take the following emergency mitigation steps:

  1. Update WordPress Core now: Make sure your version of WordPress has been updated to the latest secure version, i.e WordPress 6.9.5 or WordPress 7.0.2 (or version 6.8.6 for branch 6.8). Even though WordPress has released Forced Auto-Update, you must confirm manually via the admin dashboard.
  2. Check new admin users: Immediately audit account register in the menu users > all users. Remove administrator accounts that you don’t know or suspect made by hackers.
  3. Use Web Application Firewall (WAF): Make sure your WAF protection service (such as CloudFlare or Sucuri) is active to block the suspicious Batch Batch Payload request pattern.
  4. Emergency Mitigation (if you can’t update): Block Anonymous Access to Endpoint Rest API /batch/v1 At the server level or use a temporary API route security plugin.

CONCLUSION EDITORIAL LIFETEKNO.COM

Threat wp2shell wordpress vulnerability is a hard alarm for the global web ecosystem. The presence of AI not only helps developers speed up application creation, but also provides super sensitive weapons for hackers to find loopholes in hours. Ignoring the current system update is tantamount to leaving the door of the house wide open in the middle of the storm.

Leave a Reply

Your email address will not be published. Required fields are marked *


Baca Juga

Back to top button

Adblock Detected

LidahTekno.com is supported by Google Adsense advertising to provide content for you.Please consider disabling AdBlocker or adding us to your whitelist so we can continue providing the best technology information and tips.Thank you for your support!