wp2shell
Coverage of wp2shell in the Nexus archive.
- What happens if you visit a WordPress site hacked through wp2shell?
WordPress patched a critical core vulnerability chain called wp2shell, which allows attackers to gain full control of sites without authentication, leading to risks like credential theft, malware delivery, and malicious redirects for visitors. Attackers have already begun exploiting the flaw, injecting harmful content and compromising user trust.
- WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers are exploiting two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, codenamed wp2shell, to achieve unauthenticated remote code execution and fully compromise vulnerable websites. The exploitation has led to increased mass scanning of WordPress sites.
- 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
A new vulnerability called 'WP2Shell' has been discovered in WordPress, allowing remote takeover. Attackers are actively exploiting CVE-2026-60137 and CVE-2026-63030 to target millions of sites.
- WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public exploits have been released for the critical 'wp2shell' remote code execution vulnerabilities affecting WordPress Core, requiring immediate patching by administrators. The vulnerabilities allow attackers to execute arbitrary code on vulnerable WordPress installations.
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
A new WordPress core vulnerability named wp2shell allows unauthenticated attackers to execute arbitrary code via an anonymous HTTP request. The flaw exists in the core software, making even installations with no plugins exploitable. WordPress released updates 6.9.5 and 7.0.2 to address the issue, which previously affected all 6.9 and 7.0 versions.