Two newly discovered WordPress vulnerabilities working together allow hackers complete control of websites without needing login credentials.
Security researchers have discovered a dangerous combination of two separate security weaknesses in WordPress, the platform that powers nearly half of all websites on the internet. When attackers chain these flaws together, they can break into a website completely and take total control—without ever needing a password or login credentials. The vulnerabilities have been labeled CVE-2026-63030 and CVE-2026-60137, and researchers are calling this dangerous pairing "wp2she."
What makes this situation particularly urgent is that the attack works on undefended websites. Think of it like discovering that a building has two doors that, when used together in sequence, bypass the security guard entirely. A hacker exploiting these flaws can inject malicious code directly into affected servers, potentially installing spyware, stealing data, or taking the entire website offline.
The threat has already expanded beyond theoretical danger. Real-world attackers are weaponizing these vulnerabilities in active campaigns. One emerging threat uses a type of malware called ENCFORGE, which specifically hunts for and corrupts artificial intelligence model files stored through a tool called Langflow. This targeting suggests attackers are now deliberately going after businesses working with AI systems.
WordPress isn't just used by bloggers and small businesses—major corporations, media outlets, and government organizations rely on it. A successful attack through these vulnerabilities gives hackers the ability to:
The damage isn't limited to the business being attacked. When a website gets compromised this way, visitors can unknowingly download malware onto their own devices. This transforms your website from a business asset into a liability.
If you operate a WordPress website, immediate action is necessary:
For AI users specifically: If you're using Langflow or similar AI tools, prioritize backing up your trained models and ensure your systems receive updates the moment vendors release them.
Website security isn't a one-time task but an ongoing responsibility—stay vigilant and stay updated.
Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.
Explore IT Chapters →