{"id":30003,"date":"2026-07-31T09:55:18","date_gmt":"2026-07-31T07:55:18","guid":{"rendered":"https:\/\/perseus.de\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/"},"modified":"2026-08-16T14:56:05","modified_gmt":"2026-08-16T12:56:05","slug":"active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites","status":"publish","type":"post","link":"https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/","title":{"rendered":"Active attacks on WordPress: Critical vulnerability allows the complete takeover of websites"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"30003\" class=\"elementor elementor-30003 elementor-28873\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-dcf4ec4 e-flex e-con-boxed e-con e-parent\" data-id=\"dcf4ec4\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e1db58c elementor-widget elementor-widget-image\" data-id=\"e1db58c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"800\" height=\"200\" src=\"https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-1024x256.png\" class=\"attachment-large size-large wp-image-30037\" alt=\"In the event of a current attack pattern or a security vulnerability, Perseus sends out warning emails containing specific countermeasures.\" srcset=\"https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-1024x256.png 1024w, https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-300x75.png 300w, https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-768x192.png 768w, https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN.png 1200w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-1258a43 e-flex e-con-boxed e-con e-parent\" data-id=\"1258a43\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-2de4e88 e-con-full e-flex e-con e-child\" data-id=\"2de4e88\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4982c80 elementor-widget elementor-widget-text-editor\" data-id=\"4982c80\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<h6>30.07.2026<\/h6>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8348bc5 elementor-widget elementor-widget-heading\" data-id=\"8348bc5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Active attacks on WordPress: Critical vulnerability allows the complete takeover of websites\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-eb03842 e-con-full e-flex e-con e-child\" data-id=\"eb03842\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-91d0988 elementor-widget elementor-widget-text-editor\" data-id=\"91d0988\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>  <\/p><p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"194\" data-end=\"422\"><strong data-start=\"194\" data-end=\"422\">Currently, there is an increasing wave of attacks on WordPress websites worldwide. Cybercriminals exploit critical vulnerabilities to attack vulnerable systems and, in the worst case, take over completely. <\/strong><\/p><p data-start=\"427\" data-end=\"631\"><strong data-start=\"427\" data-end=\"631\">It is particularly critical that the vulnerability is located directly in the WordPress core and not in a plugin or theme. This can affect numerous WordPress installations. <\/strong><\/p><p data-start=\"636\" data-end=\"960\"><strong data-start=\"636\" data-end=\"960\">We are also currently observing an increasing number of security incidents in connection with compromised WordPress installations as part of our incident response missions. This underscores the importance of updating affected systems in a timely manner and checking for signs of compromise. <\/strong><\/p><p data-start=\"965\" data-end=\"1129\"><strong data-start=\"965\" data-end=\"1129\">In the following, you will learn how the attack chain works, why it poses a high risk to companies and what measures are now recommended.<\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-ceb0f40 e-flex e-con-boxed e-con e-parent\" data-id=\"ceb0f40\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-ffbdc12 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"ffbdc12\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-02dd0e9 e-flex e-con-boxed e-con e-parent\" data-id=\"02dd0e9\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-16d621d e-con-full e-flex e-con e-child\" data-id=\"16d621d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-89904c7 elementor-widget elementor-widget-text-editor\" data-id=\"89904c7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>What happened?<\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-fae461d e-con-full e-flex e-con e-child\" data-id=\"fae461d\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-0f04793 elementor-widget elementor-widget-text-editor\" data-id=\"0f04793\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"752\" data-end=\"1158\">The attack chain known as <strong data-start=\"772\" data-end=\"786\">&#8220;WP2Shell&#8221;<\/strong> combines two vulnerabilities (<strong data-start=\"842\" data-end=\"860\">CVE-2026-63030<\/strong> and <strong data-start=\"865\" data-end=\"883\">CVE-2026-60137<\/strong>). Together, they enable attackers to manipulate database queries (<strong data-start=\"962\" data-end=\"1020\">SQL injection \u2013 the injection of database commands<\/strong>) and then execute their own malicious code on the web server (<strong data-start=\"1088\" data-end=\"1156\">remote code execution \u2013 the execution of commands remotely<\/strong>). <\/p><p data-start=\"1160\" data-end=\"1683\"><strong data-start=\"1181\" data-end=\"1212\">No valid credentials are required<\/strong> for the attack. Instead, the attackers use the vulnerabilities to bypass security mechanisms and take control of a vulnerable WordPress installation. After a successful compromise, <strong data-start=\"1458\" data-end=\"1556\">web shells (programs that give attackers permanent remote access to the server)<\/strong> or other backdoors can be installed, websites can be manipulated, malware can be spread or confidential data can be stolen.  <\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-54c68ef e-flex e-con-boxed e-con e-parent\" data-id=\"54c68ef\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-96849ac elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"96849ac\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-174b215 e-flex e-con-boxed e-con e-parent\" data-id=\"174b215\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-e560a6b e-con-full e-flex e-con e-child\" data-id=\"e560a6b\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-013b67e elementor-widget elementor-widget-text-editor\" data-id=\"013b67e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>Why is this so critical?<\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a72ed48 e-con-full e-flex e-con e-child\" data-id=\"a72ed48\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-db8754f elementor-widget elementor-widget-text-editor\" data-id=\"db8754f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"1721\" data-end=\"1919\">The attack chain achieves one of the highest possible severity levels with a <strong data-start=\"1758\" data-end=\"1794\">CVSS score of 9.8 out of 10 points<\/strong> . However, it is particularly critical that the vulnerability is already being actively exploited. <\/p><p data-start=\"1921\" data-end=\"2358\">We are also currently observing an increasing number of security incidents in connection with compromised WordPress installations as part of our <strong data-start=\"1959\" data-end=\"1989\">incident response missions<\/strong> . In several cases, attackers gained permanent access to the web server via installed <strong data-start=\"2172\" data-end=\"2185\">web shells<\/strong> , stole sensitive data or used compromised systems to attack other websites within the same hosting environment. <\/p><p data-start=\"2360\" data-end=\"2661\">Since WordPress is one of the world&#8217;s most widely used <strong data-start=\"2416\" data-end=\"2453\">content management systems (CMS)<\/strong> and many websites are publicly accessible, attackers automatically search for vulnerable installations. Systems that are not updated can be compromised within a short period of time. <\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-54465d1 e-flex e-con-boxed e-con e-parent\" data-id=\"54465d1\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d02be9e elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"d02be9e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-d3f9227 e-flex e-con-boxed e-con e-parent\" data-id=\"d3f9227\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-6059711 e-con-full e-flex e-con e-child\" data-id=\"6059711\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-26eea72 elementor-widget elementor-widget-text-editor\" data-id=\"26eea72\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>What is affected? <\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-724b6c6 e-con-full e-flex e-con e-child\" data-id=\"724b6c6\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-f0c2fb4 elementor-widget elementor-widget-text-editor\" data-id=\"f0c2fb4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<table class=\"m_-5732044313742528098list_block\" role=\"presentation\" border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td><div><ul><li>WordPress 6.8.0-6.8.5 (only affected by CVE-2026-60137)<\/li><li>WordPress 6.9.0 to 6.9.4<\/li><li>WordPress 7.0.0 to 7.0.1<\/li><li>WordPress 7.1 beta<\/li><\/ul><\/div><\/td><\/tr><\/tbody><\/table><table role=\"presentation\" border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td><div><p>The following WordPress versions are not affected, as the vulnerability has already been fixed there. You should update your systems to these versions: <\/p><\/div><\/td><\/tr><\/tbody><\/table><table class=\"m_-5732044313742528098list_block\" role=\"presentation\" border=\"0\" width=\"100%\" cellspacing=\"0\" cellpadding=\"0\"><tbody><tr><td><div><ul><li>WordPress 6.8.6<\/li><li>WordPress 6.9.5<\/li><li><a href=\"https:\/\/fwtrackfm.perseus.de\/v1\/clk\/dTRb6GPDSVCKWg8pxM9KAg,D_o9E3hEQYe8ZK2W_VeWFA,3,aHR0cHM6Ly93b3JkcHJlc3Mub3JnL25ld3MvY2F0ZWdvcnkvc2VjdXJpdHkv,1,N18xXzg0MDg4NzMzNTIzNDk3OTk5MQ,dXYx,U0lHMQ,MTAwMQ,3Q4LWOt-E_DxEZRNV5-YDp0L6MzHNghliQy0TrZf3X4\" target=\"_blank\" rel=\"noopener\" data-saferedirecturl=\"https:\/\/www.google.com\/url?q=https:\/\/fwtrackfm.perseus.de\/v1\/clk\/dTRb6GPDSVCKWg8pxM9KAg,D_o9E3hEQYe8ZK2W_VeWFA,3,aHR0cHM6Ly93b3JkcHJlc3Mub3JnL25ld3MvY2F0ZWdvcnkvc2VjdXJpdHkv,1,N18xXzg0MDg4NzMzNTIzNDk3OTk5MQ,dXYx,U0lHMQ,MTAwMQ,3Q4LWOt-E_DxEZRNV5-YDp0L6MzHNghliQy0TrZf3X4&amp;source=gmail&amp;ust=1785569004316000&amp;usg=AOvVaw03LAlQUspSm4mPIhxdSi0G\">WordPress 7.0.2<\/a><\/li><li>WordPress 7.1 beta2<\/li><\/ul><\/div><\/td><\/tr><\/tbody><\/table>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9e25b00 e-flex e-con-boxed e-con e-parent\" data-id=\"9e25b00\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-67b2d4e elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"67b2d4e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-c28550e e-flex e-con-boxed e-con e-parent\" data-id=\"c28550e\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-b5ac00b e-con-full e-flex e-con e-child\" data-id=\"b5ac00b\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4467aca elementor-widget elementor-widget-text-editor\" data-id=\"4467aca\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>How can I protect myself? <\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-990ca5f e-con-full e-flex e-con e-child\" data-id=\"990ca5f\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-56e453f elementor-widget elementor-widget-text-editor\" data-id=\"56e453f\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"3441\" data-end=\"3632\">Companies and website operators should check promptly whether their WordPress installation is affected and take appropriate protective measures. In particular, we recommend the following steps: <\/p><ul data-start=\"3634\" data-end=\"4910\"><li data-section-id=\"1ivqdda\" data-start=\"3634\" data-end=\"3764\"><strong data-start=\"3636\" data-end=\"3684\">Check the WordPress version you are using<\/strong> and install the available security updates as soon as possible.<\/li><li data-section-id=\"18z9c2i\" data-start=\"3766\" data-end=\"3989\"><strong data-start=\"3768\" data-end=\"3862\">Check your WordPress installation for signs of possible compromise.<\/strong>  In particular, check whether unknown administrator users have been created or existing user rights have been changed.<\/li><li data-section-id=\"1y850d7\" data-start=\"3991\" data-end=\"4206\"><strong data-start=\"3993\" data-end=\"4055\">Check installed plugins, themes, and files<\/strong> for unexpected changes or unknown extensions. These can indicate manipulation of the website or installed backdoors. <\/li><li data-section-id=\"1xb48c7\" data-start=\"4208\" data-end=\"4455\"><strong data-start=\"4210\" data-end=\"4271\">Check the web server and WordPress logs (logs)<\/strong> for unusual accesses or suspicious activity. In particular, recurring or unusual requests to the WordPress REST API can provide indications of attack attempts. <\/li><li data-section-id=\"1vbv5ww\" data-start=\"4457\" data-end=\"4652\"><strong data-start=\"4459\" data-end=\"4516\">Scan the web server for suspicious files<\/strong>, such as <strong data-start=\"4537\" data-end=\"4620\">web shells (programs that allow attackers to gain permanent remote access)<\/strong> or other unknown scripts.<\/li><li data-section-id=\"1emv19o\" data-start=\"4654\" data-end=\"4910\"><strong data-start=\"4656\" data-end=\"4713\">If there are indications of a compromise,<\/strong> it is advisable to change all WordPress, database and hosting credentials. It should also be checked whether a restore from a trusted backup is necessary. <\/li><\/ul><blockquote data-start=\"4912\" data-end=\"5359\"><p data-start=\"4914\" data-end=\"5359\"><strong data-start=\"4914\" data-end=\"4926\">Important:<\/strong> A security update prevents further attacks, but does not remove backdoors or malware that have already been installed. If there is a suspicion of a successful compromise, the incident should first be forensically investigated. Only then should a decision be made on whether to clean up or restore the system in order to secure possible evidence and assess the actual scope of the attack.  <\/p><\/blockquote>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-a2790c7 e-flex e-con-boxed e-con e-parent\" data-id=\"a2790c7\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d4feb2c elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"d4feb2c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-7faf510 e-flex e-con-boxed e-con e-parent\" data-id=\"7faf510\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-9a087a2 e-con-full e-flex e-con e-child\" data-id=\"9a087a2\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4a4eba5 elementor-widget elementor-widget-text-editor\" data-id=\"4a4eba5\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><b>Conclusion  <\/b><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-f63aea7 e-con-full e-flex e-con e-child\" data-id=\"f63aea7\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-e249ee4 elementor-widget elementor-widget-text-editor\" data-id=\"e249ee4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p class=\"PDq2pG_selectionAnchorContainer\" data-start=\"5376\" data-end=\"5708\">The current wave of attacks once again illustrates how quickly cybercriminals exploit critical vulnerabilities in widely used web applications. Especially with publicly accessible systems such as WordPress, there can be only a few hours or days between the publication of a security vulnerability and the first attacks. <\/p><p data-start=\"5710\" data-end=\"6003\">Companies should therefore not only install the available security updates promptly, but also regularly check their systems for signs of compromise. This includes, in particular, the control of user accounts, installed extensions and web server logs. <\/p><p class=\"\" data-start=\"6005\" data-end=\"6372\">If you want to take a closer look at attacks on content management systems and suitable protective measures, you can find more information in our <strong data-start=\"6162\" data-end=\"6205\">white paper &#8220;<a href=\"https:\/\/perseus.de\/content-management-systeme-unter-beschuss\/\">CMS Systems under Attack<\/a>&#8220;.<\/strong> In it, we show typical attack methods, common vulnerabilities and proven measures that can be used to effectively secure WordPress and other CMS solutions. <\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-8530d6c e-flex e-con-boxed e-con e-parent\" data-id=\"8530d6c\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3bbb54c elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"3bbb54c\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f2d97c9 elementor-widget elementor-widget-text-editor\" data-id=\"f2d97c9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><i>Do you want to stay informed about current threats and security vulnerabilities?<\/i><\/p><p><i>Subscribe to our newsletter and receive important warnings, recommendations for action and assessments of current cyber risks directly in your inbox.<\/i><\/p><p><b>Sources &amp; Further Information<\/b><\/p><ul><li data-section-id=\"pt2o0k\" data-start=\"235\" data-end=\"425\"><strong data-start=\"237\" data-end=\"332\">CrowdSec \u2013 Vulnerability Tracking Report: CVE-2026-63030 \u2013 WordPress &#8220;WP2Shell&#8221; SQLi-to-RCE<\/strong><br \/><a class=\"decorated-link\" href=\"https:\/\/www.crowdsec.net\/vulntracking-report\/cve-2026-63030-wordpress-wp2shell-sqli-to-rce\" target=\"_new\" rel=\"noopener\" data-start=\"335\" data-end=\"425\">https:\/\/www.crowdsec.net\/vulntracking-report\/cve-2026-63030-wordpress-wp2shell-sqli-to-rce<\/a><\/li><li data-section-id=\"1wpxktt\" data-start=\"427\" data-end=\"510\"><strong data-start=\"429\" data-end=\"462\">WordPress \u2013 Security Releases<\/strong><br \/><a class=\"decorated-link\" href=\"https:\/\/wordpress.org\/news\/category\/security\/\" target=\"_new\" rel=\"noopener\" data-start=\"465\" data-end=\"510\">https:\/\/wordpress.org\/news\/category\/security\/<\/a><\/li><li data-section-id=\"itoaa7\" data-start=\"512\" data-end=\"627\"><strong data-start=\"514\" data-end=\"577\">NIST National Vulnerability Database (NVD) &#8211; CVE-2026-63030<\/strong><br \/><a class=\"decorated-link\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-63030\" target=\"_new\" rel=\"noopener\" data-start=\"580\" data-end=\"627\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-63030<\/a><\/li><li data-section-id=\"1c6r24v\" data-start=\"629\" data-end=\"744\"><strong data-start=\"631\" data-end=\"694\">NIST National Vulnerability Database (NVD) &#8211; CVE-2026-60137<\/strong><br \/><a class=\"decorated-link\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-60137\" target=\"_new\" rel=\"noopener\" data-start=\"697\" data-end=\"744\">https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-60137<\/a><\/li><li data-section-id=\"rx2tup\" data-start=\"746\" data-end=\"882\"><strong data-start=\"748\" data-end=\"815\">Escape Technologies \u2013 WP2Shell: CVE-2026-63030 &amp; CVE-2026-60137<\/strong><br \/><a class=\"decorated-link\" href=\"https:\/\/escape.tech\/blog\/wp2shell-cve-2026-63030-cve-2026-60137\/\" target=\"_new\" rel=\"noopener\" data-start=\"818\" data-end=\"882\">https:\/\/escape.tech\/blog\/wp2shell-cve-2026-63030-cve-2026-60137\/<\/a><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-9f86355 e-flex e-con-boxed e-con e-parent\" data-id=\"9f86355\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-dd90633 elementor-widget-divider--view-line elementor-widget elementor-widget-divider\" data-id=\"dd90633\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"divider.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-divider\">\n\t\t\t<span class=\"elementor-divider-separator\">\n\t\t\t\t\t\t<\/span>\n\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Currently, there is an increasing wave of attacks on WordPress websites worldwide. Cybercriminals exploit critical vulnerabilities to attack vulnerable systems and, in the worst case, take over completely. <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[22,64],"tags":[],"class_list":["post-30003","post","type-post","status-publish","format-standard","hentry","category-gefahrenwarnung","category-hazard-warning"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Active attacks on WordPress: Critical vulnerability allows the complete takeover of websites - Perseus Technologies<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Active attacks on WordPress: Critical vulnerability allows the complete takeover of websites - Perseus Technologies\" \/>\n<meta property=\"og:description\" content=\"Currently, there is an increasing wave of attacks on WordPress websites worldwide. Cybercriminals exploit critical vulnerabilities to attack vulnerable systems and, in the worst case, take over completely.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/\" \/>\n<meta property=\"og:site_name\" content=\"Perseus Technologies\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-31T07:55:18+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-16T12:56:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-1024x256.png\" \/>\n<meta name=\"author\" content=\"Anastasia Pamoukis\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Anastasia Pamoukis\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\\\/\"},\"author\":{\"name\":\"Anastasia Pamoukis\",\"@id\":\"https:\\\/\\\/perseus.de\\\/#\\\/schema\\\/person\\\/6c87a2feea6439d0ead16c8f0f07e40b\"},\"headline\":\"Active attacks on WordPress: Critical vulnerability allows the complete takeover of websites\",\"datePublished\":\"2026-07-31T07:55:18+00:00\",\"dateModified\":\"2026-08-16T12:56:05+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\\\/\"},\"wordCount\":937,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Coverbild-Gefahrenwarnung_EN-1024x256.png\",\"articleSection\":[\"Gefahrenwarnung\",\"Hazard warning\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/perseus.de\\\/en\\\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\\\/\",\"url\":\"https:\\\/\\\/perseus.de\\\/en\\\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\\\/\",\"name\":\"Active attacks on WordPress: Critical vulnerability allows the complete takeover of websites - Perseus Technologies\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Coverbild-Gefahrenwarnung_EN-1024x256.png\",\"datePublished\":\"2026-07-31T07:55:18+00:00\",\"dateModified\":\"2026-08-16T12:56:05+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/perseus.de\\\/en\\\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\\\/#primaryimage\",\"url\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Coverbild-Gefahrenwarnung_EN-1024x256.png\",\"contentUrl\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Coverbild-Gefahrenwarnung_EN-1024x256.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/perseus.de\\\/en\\\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/perseus.de\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Active attacks on WordPress: Critical vulnerability allows the complete takeover of websites\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/perseus.de\\\/#website\",\"url\":\"https:\\\/\\\/perseus.de\\\/\",\"name\":\"perseus-web.de\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/perseus.de\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/perseus.de\\\/#organization\",\"name\":\"perseus-web.de\",\"url\":\"https:\\\/\\\/perseus.de\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/perseus.de\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/PerseusTechnologie_Color-2.png\",\"contentUrl\":\"https:\\\/\\\/perseus.de\\\/wp-content\\\/uploads\\\/2025\\\/03\\\/PerseusTechnologie_Color-2.png\",\"width\":536,\"height\":172,\"caption\":\"perseus-web.de\"},\"image\":{\"@id\":\"https:\\\/\\\/perseus.de\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/perseus.de\\\/#\\\/schema\\\/person\\\/6c87a2feea6439d0ead16c8f0f07e40b\",\"name\":\"Anastasia Pamoukis\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g\",\"caption\":\"Anastasia Pamoukis\"},\"sameAs\":[\"https:\\\/\\\/perseus.de\"],\"url\":\"https:\\\/\\\/perseus.de\\\/en\\\/author\\\/anastasia-pamoukis\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Active attacks on WordPress: Critical vulnerability allows the complete takeover of websites - Perseus Technologies","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/","og_locale":"en_US","og_type":"article","og_title":"Active attacks on WordPress: Critical vulnerability allows the complete takeover of websites - Perseus Technologies","og_description":"Currently, there is an increasing wave of attacks on WordPress websites worldwide. Cybercriminals exploit critical vulnerabilities to attack vulnerable systems and, in the worst case, take over completely.","og_url":"https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/","og_site_name":"Perseus Technologies","article_published_time":"2026-07-31T07:55:18+00:00","article_modified_time":"2026-08-16T12:56:05+00:00","og_image":[{"url":"https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-1024x256.png","type":"","width":"","height":""}],"author":"Anastasia Pamoukis","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Anastasia Pamoukis","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/#article","isPartOf":{"@id":"https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/"},"author":{"name":"Anastasia Pamoukis","@id":"https:\/\/perseus.de\/#\/schema\/person\/6c87a2feea6439d0ead16c8f0f07e40b"},"headline":"Active attacks on WordPress: Critical vulnerability allows the complete takeover of websites","datePublished":"2026-07-31T07:55:18+00:00","dateModified":"2026-08-16T12:56:05+00:00","mainEntityOfPage":{"@id":"https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/"},"wordCount":937,"commentCount":0,"publisher":{"@id":"https:\/\/perseus.de\/#organization"},"image":{"@id":"https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/#primaryimage"},"thumbnailUrl":"https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-1024x256.png","articleSection":["Gefahrenwarnung","Hazard warning"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/","url":"https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/","name":"Active attacks on WordPress: Critical vulnerability allows the complete takeover of websites - Perseus Technologies","isPartOf":{"@id":"https:\/\/perseus.de\/#website"},"primaryImageOfPage":{"@id":"https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/#primaryimage"},"image":{"@id":"https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/#primaryimage"},"thumbnailUrl":"https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-1024x256.png","datePublished":"2026-07-31T07:55:18+00:00","dateModified":"2026-08-16T12:56:05+00:00","breadcrumb":{"@id":"https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/#primaryimage","url":"https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-1024x256.png","contentUrl":"https:\/\/perseus.de\/wp-content\/uploads\/2026\/07\/Coverbild-Gefahrenwarnung_EN-1024x256.png"},{"@type":"BreadcrumbList","@id":"https:\/\/perseus.de\/en\/active-attacks-on-wordpress-critical-vulnerability-allows-the-complete-takeover-of-websites\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/perseus.de\/"},{"@type":"ListItem","position":2,"name":"Active attacks on WordPress: Critical vulnerability allows the complete takeover of websites"}]},{"@type":"WebSite","@id":"https:\/\/perseus.de\/#website","url":"https:\/\/perseus.de\/","name":"perseus-web.de","description":"","publisher":{"@id":"https:\/\/perseus.de\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/perseus.de\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/perseus.de\/#organization","name":"perseus-web.de","url":"https:\/\/perseus.de\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/perseus.de\/#\/schema\/logo\/image\/","url":"https:\/\/perseus.de\/wp-content\/uploads\/2025\/03\/PerseusTechnologie_Color-2.png","contentUrl":"https:\/\/perseus.de\/wp-content\/uploads\/2025\/03\/PerseusTechnologie_Color-2.png","width":536,"height":172,"caption":"perseus-web.de"},"image":{"@id":"https:\/\/perseus.de\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/perseus.de\/#\/schema\/person\/6c87a2feea6439d0ead16c8f0f07e40b","name":"Anastasia Pamoukis","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/88febef1895859fc3a543c774ae6bc44cde0f02199f7f792af67eaf196406342?s=96&d=mm&r=g","caption":"Anastasia Pamoukis"},"sameAs":["https:\/\/perseus.de"],"url":"https:\/\/perseus.de\/en\/author\/anastasia-pamoukis\/"}]}},"_links":{"self":[{"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/posts\/30003","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/comments?post=30003"}],"version-history":[{"count":4,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/posts\/30003\/revisions"}],"predecessor-version":[{"id":30040,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/posts\/30003\/revisions\/30040"}],"wp:attachment":[{"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/media?parent=30003"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/categories?post=30003"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/perseus.de\/en\/wp-json\/wp\/v2\/tags?post=30003"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}