Public WordPress wp2shell Exploit Triggers Global RCE Wave

TL;DR Summary
Attackers are abusing two flaws, CVE-2026-63030 and CVE-2026-60137 (wp2shell), to achieve unauthenticated remote code execution on stock WordPress installs. Public PoCs and AI-assisted tooling have spurred widespread scanning and exploitation, including admin account creation, malicious plugins, and web shells like CMSmap. While automatic updates and some WAF protections have reduced risk, many sites may remain unpatched; defenders should patch immediately and audit for indicators of compromise such as new admins and suspicious plugins.
- WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning The Hacker News
- Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities The Cloudflare Blog
- CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core Rapid7
- Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk TechCrunch
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More The Hacker News
Reading Insights
Total Reads
0
Unique Readers
8
Time Saved
4 min
vs 5 min read
Condensed
92%
911 → 73 words
Want the full story? Read the original article
Read on The Hacker News