< BACK TO NEWS
negativeSYS.SOURCE: The Hacker News2026-07-21T14:29:30+05:30

Widespread Exploitation of WordPress wp2shell Vulnerabilities via Public Exploit Code

Attackers are exploiting two critical WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) to achieve unauthenticated remote code execution, leading to widespread compromise. Public exploit code has enabled mass scanning and post-exploitation activities, including web shell deployment and backdoor creation.

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.

The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell.

"By the early hours of Saturday morning (UTC), successful exploitation was already well

Read original article

*** END OF TRANSMISSION ***