#2
BleepingComputer
general
July 21, 2026 at 16:41 UTC
Critical wp2shell WordPress flaws exploited to install webshells
By Bill Toulas
AI Summary
Two critical WordPress Core vulnerabilities — CVE-2026-63030 and CVE-2026-60137, dubbed 'wp2shell' — are being chained by attackers to achieve unauthenticated RCE, deploy persistent webshells, and install malicious plugins. Mass scanning began within hours of a public exploit being released, and exploitation was confirmed by early Saturday morning UTC, making immediate patching urgent for the roughly 40% of websites running WordPress.
Relevance score: 90.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →