CVE Tools

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

The Hacker NewsBy The Hacker News

Reported exploitedWordPress core

Our summary

Attackers are actively exploiting two critical vulnerabilities in WordPress—CVE-2026-63030 and CVE-2026-60137—to achieve unauthenticated remote code execution (RCE) and fully compromise vulnerable sites. These flaws, collectively named wp2shell, allow attackers to execute arbitrary code on default WordPress installations without requiring authentication or plugins. Security researchers have reported widespread exploitation attempts globally, with malicious actors uploading web shells, stealing credentials, and creating backdoor admin accounts. Cloudflare and Wiz have confirmed that a significant percentage of WordPress deployments were initially exposed to these issues, though remediation efforts have reduced exposure.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store