'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

2026-07-21T02:51:38Z30dfd617faee9dcfcddca20e202f44498d21af191a670c978f06b7043e18ec79
cve-2026-60137cve-2026-63030exploitincident-responsemass-exploitationpatchingrceremote-code-executionwafweb-applicationwordpresswp2shell

What happened

A newly disclosed 'WP2Shell' attack is being widely exploited days after disclosure by chaining CVE-2026-60137 and CVE-2026-63030 to achieve remote takeover of WordPress sites. Attackers are scanning and mass-exploiting a very large WordPress footprint, enabling full site compromise, code execution, plugin/theme tampering, and potential lateral movement. Immediate mitigation: apply vendor patches or recommended hotfixes, remove known web shells, block exploit indicators with WAF/signature rules, isolate and restore affected sites from clean backups, and rotate credentials and keys.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
30dfd617faee9dcfcddca20e202f44498d21af191a670c978f06b7043e18ec79
Enrichment time
2026-07-21T02:51:38Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover · Baitaphish