🔴 Critical | Source: The Hacker News
Two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137 (collectively dubbed wp2shell), are being actively exploited in the wild. When chained together, they allow unauthenticated attackers to achieve remote code execution and full site compromise without any credentials. Mass scanning activity began almost immediately after a public exploit was released, significantly raising the risk for unpatched WordPress installations.
Security Architect’s Take: Audit your organisation’s WordPress estate immediately and apply available patches or mitigations without delay. If you host WordPress on cloud infrastructure (EC2, App Service, Cloud Run, etc.), consider placing WAF rules blocking wp2shell exploit patterns at the edge while patching is carried out, and review web application firewall logs for scanning activity originating from the past 72 hours.
Original advisory: WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning