'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
ID: bc926355-6d5a-54e3-9904-a43d67b39a57
STIX ID: report--bc926355-6d5a-54e3-9904-a43d67b39a57
Feed Name: Dark Reading
Attackers are widely exploiting a chained pair of WordPress vulnerabilities (CVE-2026-60137 and CVE-2026-63030), dubbed “WP2Shell,” which together allow unauthenticated remote code execution on default WordPress installations. The flaws affect multiple 6.9.x and 7.0.x versions; public PoCs and frontier AI-assisted exploit development accelerated attacks, with honeypots logging tens of thousands of attempts, over 100 backdoor admin accounts, and malware distribution activity. WordPress released forced auto-updates and patches on July 17; organizations are urged to inspect instances for malicious accounts, plugins, and files and to update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
