Post
CRITICAL

Critical wp2shell WordPress Flaws Exploited to Install Webshells

· rce · cve · vulnerability

Attackers are exploiting a pair of critical WordPress Core flaws — CVE-2026- 63030 and CVE-2026-60137 — codenamed “wp2shell,” to deploy persistent webshells and install malicious plugins on compromised sites. Combined, the two vulnerabilities enable unauthenticated remote code execution and full site compromise. A public exploit has fueled mass scanning since early Saturday UTC, and both CVEs have since been added to CISA’s Known Exploited Vulnerabilities catalog. Sites running WordPress Core should patch immediately and check for unauthorized plugins or webshell files.