Post
CRITICAL

WordPress wp2shell Vulnerabilities Under Mass Exploitation

· rce · cve · vulnerability · wordpress

Attackers are chaining two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, in a technique dubbed “wp2shell” to achieve unauthenticated remote code execution. A public exploit surfaced days after disclosure, and mass scanning began almost immediately, putting millions of WordPress sites at risk of full compromise. Site owners should patch affected components immediately and review logs for signs of exploitation attempts.