logo

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

ID: 550b5499-5ebb-5695-a0e9-cd12b65f7ed6

STIX ID: report--550b5499-5ebb-5695-a0e9-cd12b65f7ed6

Feed Name: The Hacker News

Threat Score
90/100

Date Published: 2026-07-21

Date Updated: 2026-07-21

Author: [email protected] (The Hacker News)

...
...

Two critical WordPress flaws (CVE-2026-63030 and CVE-2026-60137), collectively dubbed wp2shell, are being actively exploited in the wild to achieve unauthenticated RCE on stock WordPress installations; attackers have used public PoC code and AI-assisted development to scale scans and compromises, deploying malicious plugins, web shells (including a 150 KB CMSmap-like shell), creating backdoor admin accounts, and attempting to install RATs. Telemetry from multiple vendors shows widespread scanning and exploitation across many countries, with defenders urged to patch immediately and hunt for indicators of compromise even after applying fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.