By Interestana AI Editorial — AI-drafted, human-overseen. How we report
WordPress wp2shell Exploitation Accelerates After Public Exploit Release

Attackers have escalated exploitation of two critical vulnerabilities within WordPress, collectively known as wp2shell, which allow for unauthenticated remote code execution (RCE) and complete compromise of affected websites. The vulnerabilities, tracked as CVE-2026-63030 and CVE-2026-60137, became a significant concern following the public release of an exploit. By Saturday morning UTC, successful exploitation was already being observed, indicating a rapid adoption by malicious actors.
The wp2shell vulnerabilities, when chained together, permit an unauthenticated attacker to gain full control over a vulnerable WordPress installation. This level of access means attackers can deploy malware, steal sensitive data, deface websites, or use the compromised server for further malicious activities, such as launching phishing campaigns or participating in botnets. The ease of exploitation, amplified by the public availability of the exploit code, has led to widespread scanning of the internet for vulnerable WordPress sites.
Security researchers have noted a significant increase in scanning activity targeting WordPress sites since the exploit became public. This surge in malicious activity underscores the urgency for website administrators to patch their systems. The combination of these two flaws presents a severe risk, as it bypasses authentication mechanisms and directly leads to code execution, a highly sought-after capability for attackers. The specific details of the vulnerabilities and their exploitation are being closely monitored by cybersecurity firms to develop effective mitigation strategies and detection methods.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.