What's Happening?
A new exploit chain, known as wp2shell, is being actively used to target WordPress sites, allowing unauthenticated remote code execution. The vulnerabilities, CVE-2026-63030 and CVE-2026-60137, have been exploited using public proof-of-concept code. Attackers
have been able to exfiltrate hashed credentials and execute remote code on vulnerable sites. The exploitation has been observed globally, with IP addresses from multiple countries involved. The vulnerabilities affect WordPress versions released since December 2025, and the exploit chain allows attackers to gain control over default installations without any plugins.
Why It's Important?
The widespread exploitation of these vulnerabilities poses a significant threat to organizations using WordPress, which is a popular content management system. The ability for attackers to execute code remotely without authentication can lead to data breaches, unauthorized access, and potential data manipulation. The vulnerabilities lower the technical barrier for exploitation, making it easier for attackers to compromise sites. This situation highlights the importance of timely security updates and the need for organizations to monitor their systems for signs of compromise.
What's Next?
Organizations using WordPress are urged to apply security patches immediately and review their systems for indicators of compromise. Security experts recommend inspecting WordPress instances for new administrator accounts, malicious plugins, or suspicious files. The potential for further exploitation remains high, and organizations must remain vigilant. The incident underscores the need for robust security practices and the importance of keeping software up to date to protect against emerging threats.













