Critical Vulnerabilities in WordPress and SonicWall Exploited

Recent developments have exposed critical vulnerabilities in both WordPress and SonicWall’s Secure Mobile Access (SMA) 1000 series appliances, leading to active exploitation by threat actors.

WordPress ‘wp2shell’ Vulnerability

A significant security flaw, dubbed ‘wp2shell,’ has been identified in WordPress Core. This pre-authentication remote code execution (RCE) vulnerability allows unauthenticated attackers to execute arbitrary code on a default WordPress installation without the need for plugins or special configurations. The issue arises from the combination of two vulnerabilities: CVE-2026-63030, involving REST API batch-route confusion, and CVE-2026-60137, a SQL injection flaw in WordPress core. When exploited together, these vulnerabilities enable an anonymous request to escalate to code execution.

WordPress has addressed these issues by releasing versions 7.0.2 and 6.9.5, which include patches for both vulnerabilities. Given the severity of the flaw, WordPress has enabled forced automatic updates for sites running affected versions to ensure rapid mitigation. Security researchers have observed proof-of-concept exploits circulating, indicating that attackers are actively seeking to exploit this vulnerability. Site administrators are strongly advised to update their WordPress installations immediately to prevent potential compromises.

SonicWall SMA 1000 Zero-Day Exploits

In parallel, SonicWall has disclosed two zero-day vulnerabilities in its SMA 1000 series VPN appliances, identified as CVE-2026-15409 and CVE-2026-15410. CVE-2026-15409 is a server-side request forgery (SSRF) vulnerability with a CVSS score of 10.0, allowing unauthenticated remote attackers to make the appliance send requests to unintended locations. CVE-2026-15410 is a post-authentication code injection flaw with a CVSS score of 7.2, enabling authenticated attackers to execute arbitrary operating system commands under certain conditions.

These vulnerabilities have been actively exploited in the wild, with reports indicating that a previously undocumented threat actor, tracked as UTA0533, has been leveraging these flaws since June 22, 2026. The attackers have utilized multiple zero-day exploits and malware specifically designed for SonicWall SMA VPN appliances. SonicWall has released patches to address these vulnerabilities and urges customers to apply the fixes promptly to secure their systems.

The rapid identification and exploitation of these vulnerabilities underscore the evolving threat landscape in cybersecurity. Organizations must remain vigilant, ensuring timely application of security patches and maintaining robust monitoring systems to detect and respond to potential breaches. The ‘wp2shell’ vulnerability in WordPress highlights the critical need for regular updates and the importance of security in widely-used platforms. Similarly, the SonicWall SMA 1000 exploits demonstrate the necessity for organizations to secure their network appliances and be aware of emerging threats targeting such infrastructure.