Exploited in the wild WordPress Core rce WordPress web-app
Critical wp2shell WordPress flaws exploited to install webshells
CVE Tools coverage
Security researchers have confirmed that hackers are actively exploiting two critical vulnerabilities in WordPress Core—CVE-2026-63030 and CVE-2026-60137—to deploy persistent webshells and install malicious plugins on compromised systems. These flaws, collectively referred to as 'wp2shell,' allow remote code execution without requiring authentication, leveraging the REST API's batch-processing feature. WordPress has issued patches in versions 7.0.2, 6.9.5, and 6.8.6, but many sites remain unpatched. Threat actors are scanning for vulnerable installations, stealing credentials, and creating backdoor access points. Administrators are urged to update their platforms immediately and inspect logs and plugins for signs of intrusion.