
Pakistan’s National Cyber Emergency Response Team (National CERT) has issued a high-severity cybersecurity advisory, warning organisations to urgently update their WordPress websites after the discovery of two actively exploited vulnerabilities that could allow hackers to take complete control of websites without requiring login credentials or user interaction.
The advisory classified the threat as “critical”, citing widespread exploitation attempts and the public availability of proof-of-concept (PoC) exploit code. Government websites, critical information infrastructure, financial institutions, businesses and other organisations running vulnerable WordPress installations have been urged to immediately install the latest security updates.
According to National CERT, the vulnerabilities—CVE-2026-63030 (wp2shell) and CVE-2026-60137—can be chained together to remotely execute malicious code on targeted servers. The flaws exploit weaknesses in the WordPress REST API and the WP_Query class, enabling unauthenticated attackers to compromise websites and their underlying systems. National CERT assigned CVSS severity scores of 9.8 and 9.1 to the vulnerabilities, warning they could lead to complete website takeover, data theft, deployment of persistent web shells, defacement of official portals, disruption of digital services and reputational damage.
The advisory identified WordPress Core versions 7.0.0–7.0.1 and 6.9.0–6.9.4 as vulnerable, while the SQL injection flaw affects WordPress 6.8.x and later. Organisations have been directed to upgrade to WordPress 7.0.2, 6.9.5 or 6.8.6, depending on their deployment branch, and to manually verify updates instead of relying solely on automatic patching.
National CERT also recommended blocking access to the vulnerable REST API endpoint through web application firewalls where immediate patching is not possible, reviewing server logs for suspicious activity, monitoring for unauthorised files, isolating compromised systems, rotating administrative credentials after patching, and promptly reporting confirmed incidents while strengthening continuous monitoring to contain the evolving cyber threat. – ERMD
SK Hynix Considers Major Memory Chip Plant in Japan
South Korean chipmaker SK Hynix is considering building a large-scale memory chip manufacturing plant in…
Sindh, Zong Parent CMPak Agree to Develop AI-Ready Data Centre in Karachi
The Sindh government and CMPak, the parent company of Zong, have agreed to collaborate on…
New CoolClient Malware Variant Targets Organizations Across Asia and Russia
A new variant of malware capable of giving cyber attackers remote access to compromised systems…
PTA, Google Partner to Boost Child Online Safety in Pakistan
The Pakistan Telecommunication Authority (PTA) and Google LLC have signed a Memorandum of Understanding (MoU)…
Five Decades of Excellence: The Journey of Engr. Wasim Nazir
Engr. Wasim Nazir reflects on five decades of professional excellence, leadership, and lifelong learning, sharing…
China Showcases Next Generation of Robots at 2026 World Robot Conference
China opened the 2026 World Robot Conference in Beijing on Aug 19, showcasing a wide…
