
Active wp2shell flaws unleash automated WordPress webshell attacks
Hackers are abusing two critical WordPress flaws (wp2shell: CVE-2026-63030 and CVE-2026-60137) via the REST API batch-processing feature to execute code without authentication, enabling installation of malicious plugins and PHP webshells. WordPress patched versions 7.0.2, 6.9.5, and 6.8.6 with automatic updates. Security firms report mass scanning, plugin-upload abuse, admin credential harvesting, local file inclusion attempts targeting wp-config, and rogue admin accounts. Admins should update, audit logs, inspect plugins, and check /wp-content/cache for suspicious files; dashboards show ~81.6% patch rate in a sample of 124k sites. No lateral movement or data exfiltration observed yet, but monitoring continues.

