漏洞概述 漏洞名称: WP2Shell 漏洞编号: CVE-2026-60137 和 CVE-2026-63030 漏洞类型: SQL 注入漏洞和逻辑漏洞 漏洞描述: - CVE-2026-60137: 允许攻击者通过 SQL 注入漏洞操作数据库查询,访问不应暴露的数据。 - CVE-2026-63030: 在 WordPress 的 Batch REST API 中存在逻辑漏洞,允许攻击者将多个请求捆绑成一个 API 调用,从而绕过身份验证。 漏洞影响: 两个漏洞结合使用,可以实现未认证的远程代码执行(RCE),导致 WordPress 实例被完全控制。 影响范围 受影响版本: WordPress 6.9.0 - 6.8.4 和 7.0.0 - 7.0.1 影响规模: 全球范围内数以千万计的 WordPress 网站 攻击方式: 攻击者可以利用这些漏洞进行未认证的远程代码执行,获取管理员权限,安装恶意插件,窃取数据等。 修复方案 官方修复: WordPress 已于 7 月 17 日发布安全更新,修复了这两个漏洞。 建议措施: - 立即更新到最新版本的 WordPress。 - 检查 WordPress 实例,确保没有新的管理员账户、恶意插件或其他可疑文件。 - 使用自动更新系统,确保所有受影响的版本都能及时更新。 - 监控和检测潜在的 exploit 活动,如 WatchTowr 的 honeypots 所记录的那样。 相关资源 相关报道: - ClickFix's Mushrooming Ecosystem Demands New Defense Tactics - GigaWiper Lets Threat Actors Choose Their Own Destructive Attack - Turning the Tables on Email Scammers With 'ScamBuster' 作者信息 作者: Jai Vijayan 职位: 贡献作家 简介: 伊利诺伊州的 Jai Vijayan 是一位资深、屡获殊荣的技术记者,拥有超过 25 年的网络安全报道经验。 其他信息 编辑选择: - Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes - 6 GHz Wi-Fi Flaws Could Disrupt Critical Systems - 'Yellow Teams' Are Defining the Future of AI Security 订阅: - Add as a preferred source on Google - Subscribe to receive the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. 更多洞察: - Industry Reports - Webinars 您可能还喜欢: - Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days - CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks - Deja Vu: Salesforce Customers Hacked Again, Via Gainsight - Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business 页脚信息 版权: © 2026 TechTarget, Inc. d/b/a Informa TechTarget 注册信息: Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.'s registered office is 275 Grove St., Newton, MA 02466. 链接: Home, Cookie Policy, Privacy, Terms of Use