CRITICALVulnerability
Global

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

·Source: The Hacker News

Updated:

Executive Summary

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. "By the early hours of Saturday morning (UTC), successful exploitation was already well

Analysis

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. "By the early hours of Saturday morning (UTC), successful exploitation was already well

Indicators of Compromise (2)

CVE (2)
CVE-2026-63030
CVE-2026-60137
Source Attribution

Originally published by The Hacker News on Jul 21, 2026.

Related Threats