logo

'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

ID: d37bcdce-5525-5b7d-b1a6-c7ac078a923d

STIX ID: report--d37bcdce-5525-5b7d-b1a6-c7ac078a923d

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

...
...

A critical vulnerability chain named WP2Shell (CVE-2026-60137 + CVE-2026-63030) enables unauthenticated remote shell access to WordPress sites and is being actively exploited within days of disclosure, exposing potentially millions of sites to web shells, data exfiltration, pivoting, and malware deployment; site owners are urged to patch, review logs, enable WAFs, and restrict PHP execution.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.