'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

2026-07-21T08:51:36Ze5c7fba8f8dfe4ca327f361baf56b45ee24b47572d848e3a828a3f4a008af092
CVE-2026-60137CVE-2026-63030WAFWP2ShellWordPressactive-exploitationincident-responsepatch-nowremote-takeoverweb-application

What happened

Researchers disclosed the "WP2Shell" chain that attackers are actively using to achieve remote takeover of millions of Internet-facing WordPress sites by chaining CVE-2026-60137 and CVE-2026-63030. Exploitation began within days of disclosure and is widespread across a large attack surface; organizations should assume active scanning and compromise attempts. Immediate actions: apply vendor patches/updates, deploy WAF/virtual patching rules to block exploit payloads, scan for web shells/backdoors and indicators of compromise, rotate exposed credentials and secrets, and monitor/contain affected/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
e5c7fba8f8dfe4ca327f361baf56b45ee24b47572d848e3a828a3f4a008af092
Enrichment time
2026-07-21T08:51:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.