CVE Tools

Critical wp2shell WordPress flaws exploited to install webshells

BleepingComputerBy Bill Toulas

Reported exploitedWordPress Core

Our summary

Security researchers have confirmed that hackers are actively exploiting two critical vulnerabilities in WordPress Core—CVE-2026-63030 and CVE-2026-60137—to deploy persistent webshells and install malicious plugins on compromised systems. These flaws, collectively referred to as 'wp2shell,' allow remote code execution without requiring authentication, leveraging the REST API's batch-processing feature. WordPress has issued patches in versions 7.0.2, 6.9.5, and 6.8.6, but many sites remain unpatched. Threat actors are scanning for vulnerable installations, stealing credentials, and creating backdoor access points. Administrators are urged to update their platforms immediately and inspect logs and plugins for signs of intrusion.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store