Security · 5h ago
WordPress wp2shell Exploit Chain Sparks Mass Scanning Attacks
Attackers are exploiting two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, that together allow unauthenticated remote code execution. The wp2shell exploit chain enables full site compromise, with mass scanning detected within hours of public disclosure. Site administrators must apply patches immediately to prevent takeover.
Meridian48 take
The rapid weaponization of these flaws underscores the danger of chained vulnerabilities, but the real story is how slowly many WordPress sites apply critical security updates.
Read the full reporting
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning →
The Hacker News
wordpressremote-code-execution