#3
Dark Reading
general
July 20, 2026 at 21:38 UTC
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
By Jai Vijayan
AI Summary
Attackers began chaining CVE-2026-60137 and CVE-2026-63030 (dubbed 'WP2Shell') within three days of disclosure to target millions of WordPress sites with remote takeover attempts. The rapid weaponization against one of the internet's largest attack surfaces demands immediate patching for any WordPress installation running the affected components.
Relevance score: 86.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →