WP2Shell WordPress Vulnerabilities Exploited in the Wild
Reported exploitedWordPress CoreOur summary
Two recently patched WordPress vulnerabilities, known as WP2Shell (CVE-2026-60137 and CVE-2026-63030), are currently being actively exploited in the wild. These flaws allow attackers to execute arbitrary code without authentication on affected installations. The vulnerabilities impact WordPress versions 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. Patches were released in versions 6.9.5 and 7.0.2, and automatic updates have been enabled for affected sites. Cybersecurity firms including Hexastrike and WatchTowr have confirmed real-world exploitation attempts, with proof-of-concept exploits appearing soon after disclosure.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.