CVE Tools

WP2Shell WordPress Vulnerabilities Exploited in the Wild

SecurityWeekBy Eduard Kovacs

Reported exploitedWordPress Core

Our summary

Two recently patched WordPress vulnerabilities, known as WP2Shell (CVE-2026-60137 and CVE-2026-63030), are currently being actively exploited in the wild. These flaws allow attackers to execute arbitrary code without authentication on affected installations. The vulnerabilities impact WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. Patches were released in versions 6.9.5 and 7.0.2, and automatic updates have been enabled for affected sites. Cybersecurity firms including Hexastrike and WatchTowr have confirmed real-world exploitation attempts, with proof-of-concept exploits appearing soon after disclosure.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store