Skip to content
The Nexus
DossierENTITY

wp2shell

Coverage of wp2shell in the Nexus archive.

Earliest in view: Jul 17 · 21:20 UTCMost recent: Jul 21 · 14:57 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYJul 21 · 14:57 UTCMALWAREBYTES LABS
    What happens if you visit a WordPress site hacked through wp2shell?

    WordPress patched a critical core vulnerability chain called wp2shell, which allows attackers to gain full control of sites without authentication, leading to risks like credential theft, malware delivery, and malicious redirects for visitors. Attackers have already begun exploiting the flaw, injecting harmful content and compromising user trust.

  • SECURITYJul 21 · 08:59 UTCTHE HACKER NEWS
    WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

    Attackers are exploiting two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, codenamed wp2shell, to achieve unauthenticated remote code execution and fully compromise vulnerable websites. The exploitation has led to increased mass scanning of WordPress sites.

  • SECURITYJul 20 · 21:38 UTCDARK READING
    'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

    A new vulnerability called 'WP2Shell' has been discovered in WordPress, allowing remote takeover. Attackers are actively exploiting CVE-2026-60137 and CVE-2026-63030 to target millions of sites.

  • SECURITYJul 18 · 17:22 UTCBLEEPING COMPUTER
    WordPress Core "wp2shell" RCE flaws get public exploits, patch now

    Public exploits have been released for the critical 'wp2shell' remote code execution vulnerabilities affecting WordPress Core, requiring immediate patching by administrators. The vulnerabilities allow attackers to execute arbitrary code on vulnerable WordPress installations.

  • SECURITYJul 17 · 21:20 UTCTHE HACKER NEWS
    New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

    A new WordPress core vulnerability named wp2shell allows unauthenticated attackers to execute arbitrary code via an anonymous HTTP request. The flaw exists in the core software, making even installations with no plugins exploitable. WordPress released updates 6.9.5 and 7.0.2 to address the issue, which previously affected all 6.9 and 7.0 versions.