Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and malicious plugins.

Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their…

This is a republication. The original and always up to date version lives...

By chaining an SQL injection and an API vulnerability, attackers can inject code. WordPress has released an update, the finders a hotfix.

In-the-wild exploitation seen for the new WP2Shell WordPress vulnerabilities, officially tracked as CVE-2026-60137 and CVE-2026-63030.

This recap covers exploited flaws, exposed systems, malware campaigns, weak defaults, and the security gaps demanding attention.

Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity…

Attackers are chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.

Plus dozens of PoCs in the public domain

Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and malicious plugins.

Two patched WordPress vulnerabilities, chained as wp2shell, are under mass attack. AI helped find the flaw and weaponise it. Millions of sites may be exposed.

Zum Wochenende wurde die „wp2shell“-WordPress-Lücke bekannt. Seitdem beobachten IT-Sicherheitsforscher Attacken im Internet darauf.

Attackers started exploiting the critical wp2shell vulnerability chain within hours of patches being released, putting sites and their visitors at risk.

Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install…