Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits
2026-07-19T14:51:48Z•7345d8dc0fc30c62eb06896e10b19afa32724bb53145a5eead8c7c69058186c0
CISACVE-2023-4346CVE-2026-60137CVE-2026-63030DaxinDoSEY breach support tickets','supply chain risk','Nichirei','russ‑Ernst & YoungFortiSandboxFortinetHollowByteKNX ProtocolKnown Exploited VulnerabilitiesMicrosoft SharePointOpenSSLOracleRCEStupigdata breachdenial of serviceremote code executionrootkitthird-party breachwordpresswp2shell
What happened
Multiple high-impact security stories: public exploits were released for two critical WordPress Core flaws (wp2shell) — CVE-2026-63030 and CVE-2026-60137 — that can be chained for pre-auth remote code execution on default installs. Okta disclosed an 11-byte OpenSSL memory-exhaustion DoS named “HollowByte” that allows unauthenticated remote triggers of large allocations. Symantec found the long-lived China-linked Daxin kernel rootkit (with a new Stupig backdoor) on a Taiwanese manufacturer’s network dating back to 2013. CISA added multiple vulnerabilities (including Fortinet FortiSandbox, MS S‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 7345d8dc0fc30c62eb06896e10b19afa32724bb53145a5eead8c7c69058186c0
- Enrichment time
- 2026-07-19T14:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.