Public WordPress wp2shell Exploit Triggers Global RCE Wave

1 min read
Source: The Hacker News
Public WordPress wp2shell Exploit Triggers Global RCE Wave
Photo: The Hacker News
TL;DR Summary

Attackers are abusing two flaws, CVE-2026-63030 and CVE-2026-60137 (wp2shell), to achieve unauthenticated remote code execution on stock WordPress installs. Public PoCs and AI-assisted tooling have spurred widespread scanning and exploitation, including admin account creation, malicious plugins, and web shells like CMSmap. While automatic updates and some WAF protections have reduced risk, many sites may remain unpatched; defenders should patch immediately and audit for indicators of compromise such as new admins and suspicious plugins.

Share this article

Reading Insights

Total Reads

0

Unique Readers

8

Time Saved

4 min

vs 5 min read

Condensed

92%

91173 words

Want the full story? Read the original article

Read on The Hacker News