WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Key Points:
- Two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137 (collectively called wp2shell), enable unauthenticated remote code execution and full site compromise, affecting all versions since December 2025.
- Exploitation began rapidly after public proof-of-concept code was released, with attackers using multiple SQL injection techniques to gain unauthorized access and execute malicious payloads.
- Post-exploitation activities include uploading malicious plugins, harvesting admin credentials, performing local file inclusion attacks, and deploying web shells disguised as legitimate security plugins for further system control.
- Over 60% of organizations initially had vulnerable WordPress instances, with 25% exposing these to the internet; while patching has reduced exposure, many sites remain at risk due to disabled or unsuccessful automatic updates.
- Security experts urge WordPress administrators to immediately apply patches, inspect for unauthorized admin accounts and malicious files, and monitor for indicators of compromise to fully mitigate the threat.