Exploitation of two critical WordPress vulnerabilities, collectively known as wp2shell, has escalated, allowing attackers to execute remote code and fully compromise vulnerable websites. The flaws, identified as CVE-2026-63030 and CVE-2026-60137, can be exploited without authentication, making them highly dangerous. As of Saturday morning, successful exploitation was already widespread, indicating a high level of attacker interest in these vulnerabilities1. The disclosure of CVE-2026-63030 has expanded the active attack surface, making it essential for entities to prioritize mitigation based on their exposure and evidence of exploitation. The wp2shell exploits enable unauthenticated remote code execution, allowing attackers to gain complete control over vulnerable WordPress sites. This heightened exploitation activity matters to security practitioners, as it underscores the need for prompt patching and monitoring to prevent complete site compromise.
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
⚡ High Priority
Why This Matters
CVE-2026-63030 disclosure expands the active attack surface — prioritize based on your exposure and exploitation evidence.
References
- The Hacker News. (2026, July 21). WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning. *The Hacker News*. https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html
Original Source
The Hacker News
Read original →