Plus dozens of PoCs in the public domain

Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their…

This is a republication. The original and always up to date version lives...

By chaining an SQL injection and an API vulnerability, attackers can inject code. WordPress has released an update, the finders a hotfix.

In-the-wild exploitation seen for the new WP2Shell WordPress vulnerabilities, officially tracked as CVE-2026-60137 and CVE-2026-63030.

This recap covers exploited flaws, exposed systems, malware campaigns, weak defaults, and the security gaps demanding attention.

Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity…

Attackers are chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.

Plus dozens of PoCs in the public domain

Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and malicious plugins.

Two patched WordPress vulnerabilities, chained as wp2shell, are under mass attack. AI helped find the flaw and weaponise it. Millions of sites may be exposed.