logo

Critical wp2shell WordPress flaws exploited to install webshells

ID: 02dbb5ae-7c84-5bbe-bb80-0e0912aa8a81

STIX ID: report--02dbb5ae-7c84-5bbe-bb80-0e0912aa8a81

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: Bill Toulas

...
...

Critical "wp2shell" vulnerabilities in WordPress Core (CVE-2026-63030 and CVE-2026-60137) are being actively exploited in the wild to perform unauthenticated remote code execution via the REST API, enabling mass scanning, malicious plugin installation, persistent PHP webshell deployment (often under /wp-content/cache/), enumeration of admin credentials, and creation of rogue administrator accounts; site owners are urged to apply patched WordPress versions immediately and inspect logs, plugins, and file system for indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.