WARPTECHNEWS · LAB
HomeAIBusinessTechArchive
WARPTECH LAB NEWS

Warptech Lab News aggrega le notizie più rilevanti da oltre 700 fonti internazionali, con classificazione AI, TL;DR sintetici e timeline cluster su singole storie.

Navigazione

  • Home
  • Archivio
  • Editor's Brief
  • Cerca
  • Il tuo account
  • Newsletter tech/AI

Informazioni legali

  • Privacy Policy
  • Termini di servizio
  • Cookie Policy

© 2026 Sparktech S.R.L. — Tutti i diritti riservati. Sito gestito e manutenuto da Sparktech S.R.L.

Sede legale: Corso Libertà 55, 13100 Vercelli (VC), Italia · P.IVA / C.F. 02835910023 · Contatti: admin@warptechlab.com

Home
Storia in 10 fonti

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and malicious plugins.

Raccontata dableepingcomputer.comdev.toheise.desecurityweek.comthehackernews.comtechcrunch.comdarkreading.comtheregister.comthenextweb.commalwarebytes.com

Confronto fonti

6 prospettive sulla stessa storia
AI · summaries
thehackernews.comStai leggendo12 h fa

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and malicious plugins.

originale
bleepingcomputer.com4 h fa

Critical wp2shell WordPress flaws exploited to install webshells

Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers.

Leggi questa versione → originale
darkreading.com23 h fa

'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

Attackers are chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.

Leggi questa versione → originale
securityweek.com1 g fa

WP2Shell WordPress Vulnerabilities Exploited in the Wild

In-the-wild exploitation seen for the new WP2Shell WordPress vulnerabilities, officially tracked as CVE-2026-60137 and CVE-2026-63030.

Leggi questa versione → originale
thenextweb.com9 h fa

Hackers are mass-exploiting two WordPress vulnerabilities

Two patched WordPress vulnerabilities, chained as wp2shell, are under mass attack. AI helped find the flaw and weaponise it. Millions of sites may be exposed.

Leggi questa versione → originale
heise.de1 g fa

wp2shell: Critical WordPress vulnerability allows code injection via API

By chaining an SQL injection and an API vulnerability, attackers can inject code. WordPress has released an update, the finders a hotfix.

Leggi questa versione → originale

Timeline cronologica

  1. sabato 18 luglio 2026·bleepingcomputer.com

    WordPress Core "wp2shell" RCE flaws get public exploits, patch now

    Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their…

  2. domenica 19 luglio 2026·dev.to

    wp2shell: how a route confusion + a reachable SQLi become pre-auth RCE in WordPress core

    This is a republication. The original and always up to date version lives...

  3. domenica 19 luglio 2026·heise.de

    wp2shell: Critical WordPress vulnerability allows code injection via API

    By chaining an SQL injection and an API vulnerability, attackers can inject code. WordPress has released an update, the finders a hotfix.

  4. lunedì 20 luglio 2026·securityweek.com

    WP2Shell WordPress Vulnerabilities Exploited in the Wild

    In-the-wild exploitation seen for the new WP2Shell WordPress vulnerabilities, officially tracked as CVE-2026-60137 and CVE-2026-63030.

  5. lunedì 20 luglio 2026·thehackernews.com

    ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More

    This recap covers exploited flaws, exposed systems, malware campaigns, weak defaults, and the security gaps demanding attention.

  6. lunedì 20 luglio 2026·techcrunch.com

    Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk | TechCrunch

    Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity…

  7. lunedì 20 luglio 2026·darkreading.com

    'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

    Attackers are chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.

  8. lunedì 20 luglio 2026·theregister.com

    Attackers pummel critical WordPress vuln to create all sorts of mischief

    Plus dozens of PoCs in the public domain

  9. martedì 21 luglio 2026·thehackernews.com

    WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

    Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and malicious plugins.

  10. martedì 21 luglio 2026·thenextweb.com

    Hackers are mass-exploiting two WordPress vulnerabilities

    Two patched WordPress vulnerabilities, chained as wp2shell, are under mass attack. AI helped find the flaw and weaponise it. Millions of sites may be exposed.

  11. martedì 21 luglio 2026·heise.de

    WordPress-Lücke „wp2shell“ wird angegriffen

    Zum Wochenende wurde die „wp2shell“-WordPress-Lücke bekannt. Seitdem beobachten IT-Sicherheitsforscher Attacken im Internet darauf.

  12. martedì 21 luglio 2026·malwarebytes.com

    What happens if you visit a WordPress site hacked through wp2shell?

    Attackers started exploiting the critical wp2shell vulnerability chain within hours of patches being released, putting sites and their visitors at risk.

  13. martedì 21 luglio 2026·bleepingcomputer.com

    Critical wp2shell WordPress flaws exploited to install webshells

    Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install…