Exploitation in the Wild of wp2shell
ID: 6b114e7d-c1cc-53d1-947f-649e56d0183a
STIX ID: report--6b114e7d-c1cc-53d1-947f-649e56d0183a
Feed Name: Wiz Blog
This report describes a critical pre-authentication RCE chain in WordPress Core (CVE-2026-63030 & CVE-2026-60137, "wp2shell") that enables unauthenticated remote code execution across affected versions; Wiz Research observed immediate public PoCs and active exploitation in cloud-hosted WordPress instances, with post-exploitation activity including malicious plugin uploads, multiple PHP webshells (from one-liners to large obfuscated backdoors), local file inclusion attempts, user enumeration, and mass scanning. The advisory includes IOCs (file hashes and attacker IPs) and recommends immediate patching, blocking the batch REST API via WAF or disabling anonymous REST API access as temporary mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
