Exploitation of two critical WordPress vulnerabilities, collectively known as wp2shell, has escalated, allowing attackers to execute remote code and fully compromise vulnerable websites. The flaws, identified as CVE-2026-63030 and CVE-2026-60137, can be exploited without authentication, making them highly dangerous. As of Saturday morning, successful exploitation was already widespread, indicating a high level of attacker interest in these vulnerabilities1. The disclosure of CVE-2026-63030 has expanded the active attack surface, making it essential for entities to prioritize mitigation based on their exposure and evidence of exploitation. The wp2shell exploits enable unauthenticated remote code execution, allowing attackers to gain complete control over vulnerable WordPress sites. This heightened exploitation activity matters to security practitioners, as it underscores the need for prompt patching and monitoring to prevent complete site compromise.