National CERT Warns Of Critical WordPress Security Flaws Affecting Pakistan Websites

National CERT Warns Of Critical WordPress Security Flaws Affecting Pakistan Websites

Pakistan’s National Cyber Emergency Response Team (National CERT) has issued a critical cybersecurity advisory warning organizations across the country about active exploitation of severe vulnerabilities in WordPress Core that could allow attackers to gain complete control of websites without requiring any authentication. The advisory highlights that the vulnerabilities pose a significant risk to public facing websites running affected versions of WordPress, with proof of concept exploit code becoming publicly available shortly after the security flaws were disclosed. National CERT warned that exploitation attempts were detected within hours, increasing the urgency for organizations to assess their systems and apply security updates immediately. The agency noted that websites belonging to government departments, critical infrastructure operators, financial institutions, enterprises, and public hosting environments are among the most exposed if they continue to use vulnerable versions of the content management system.

According to National CERT, the primary vulnerability tracked as CVE-2026-63030, also referred to as wp2shell, affects the WordPress REST API and can be combined with another critical vulnerability, CVE-2026-60137, which is an SQL injection flaw found in the WP_Query class. By chaining these vulnerabilities together, attackers can compromise websites without valid login credentials, making the threat particularly dangerous for organizations that rely on WordPress for public services and digital operations. The advisory assigned CVSS severity scores of 9.8 and 9.1 to the vulnerabilities, reflecting their critical impact and ease of exploitation. National CERT stated that affected versions include WordPress Core 6.9.0 through 7.0.1, while WordPress 6.8.x and later are also affected depending on the specific vulnerability. Organizations operating these versions have been urged to verify their deployments and determine whether immediate remediation is required.

The advisory further warned that successful exploitation could result in complete website compromise, unauthorized SQL injection attacks, theft of sensitive information, installation of persistent web shells, disruption of online services, and significant reputational and operational damage. National CERT also cautioned that compromised web servers could be used as entry points for attackers to move laterally across enterprise networks, potentially placing additional systems and internal resources at risk. Because WordPress powers a large number of websites across Pakistan, including those used by public sector organizations and businesses, the agency stressed that administrators should treat the vulnerabilities as high priority security issues. The availability of public exploit code combined with active exploitation significantly increases the likelihood of attacks against unpatched websites.

To reduce the risk of compromise, National CERT advised organizations to immediately update WordPress Core to the latest patched versions and verify the software versions installed on all public facing websites. The advisory also recommended updating plugins and themes to their latest releases, restricting unauthenticated access to vulnerable REST API routes where possible, and deploying Web Application Firewalls if immediate patching cannot be completed. In addition, administrators have been encouraged to inspect servers for unauthorized PHP files, rotate administrator credentials after applying security updates, conduct integrity checks of WordPress core files, and continuously monitor server logs for suspicious activity. National CERT also advised organizations to isolate any systems suspected of being compromised and report confirmed incidents through its official incident reporting mechanism. The agency emphasized that timely patching, continuous monitoring, and proactive security practices remain essential to protecting Pakistan’s public facing digital infrastructure from ongoing cyber threats.

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.

Post Comment