logo

'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

ID: bc926355-6d5a-54e3-9904-a43d67b39a57

STIX ID: report--bc926355-6d5a-54e3-9904-a43d67b39a57

Feed Name: Dark Reading

Threat Score
90/100

Date Published: 2026-07-20

Date Updated: 2026-07-21

Author: Jai Vijayan

...
...

Attackers are widely exploiting a chained pair of WordPress vulnerabilities (CVE-2026-60137 and CVE-2026-63030), dubbed “WP2Shell,” which together allow unauthenticated remote code execution on default WordPress installations. The flaws affect multiple 6.9.x and 7.0.x versions; public PoCs and frontier AI-assisted exploit development accelerated attacks, with honeypots logging tens of thousands of attempts, over 100 backdoor admin accounts, and malware distribution activity. WordPress released forced auto-updates and patches on July 17; organizations are urged to inspect instances for malicious accounts, plugins, and files and to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.