CVE-2026-60137
Sfruttamento noto · CISA KEV
CVSS 5.9 MEDIUM: wordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the… EPSS 6% (93º percentile).
Data di correzione federale CISA 4 ago
Vulnerabilità ed exploit
La storia non è più solo un file-read su Windmill. Ora ci sono due fronti attivi: su WordPress i public PoC di wp2shell lasciano artefatti locali facili da riconoscere, anche quando gli indicatori di rete cambiano, e il controllo non può fermarsi alla sola caccia sugli IOC esterni.
Le fonti confermano lo sfruttamento attivo di CVE-2026-29059 su Windmill e la circolazione rapida dei PoC per CVE-2026-63030 e CVE-2026-60137 in WordPress Core. Elastic descrive shell, directory di plugin finte e tracce coerenti sui sistemi colpiti; CISA ha inserito entrambe le CVE di WordPress nel KEV, con una finestra molto stretta di patching.
Il rischio pratico è che un’istanza esposta sia già compromessa prima della correzione. Su Windmill, se è presente SUPERADMIN_SECRET, un file read diventa accesso da superadmin; su WordPress, la compromissione può emergere anche dai reperti sul disco, non solo dal traffico di rete.
20 fonti · 29 lug
Sfruttamento noto · CISA KEV
CVSS 5.9 MEDIUM: wordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the… EPSS 6% (93º percentile).
Data di correzione federale CISA 4 ago
Sfruttamento noto · CISA KEV
CVSS 7.5 HIGH: wordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue…
Data di correzione federale CISA 24 lug · data superata
EPSS 2% (81º percentile).
The Register Security
Attackers pummel critical WordPress vuln to create all sorts of mischief
Plus dozens of PoCs in the public domain
originaleElastic Security Labs
wp2shell: detecting WordPress pre-auth RCE end-to-end — Elastic Security Labs
We ran the wp2shell WordPress RCE chain end-to-end with Elastic Defend.
originaleThe Hacker News
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
VulnCheck says attackers are exploiting Windmill CVE-2026-29059 to read server files, with about 170 vulnerable systems exposed in 24 countries.
originalePart of the PlainSec briefing for 2026-07-17
Every edition of this story: wp2shell entra in campo, Windmill resta sotto attacco