Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits

2026-07-19T14:51:48Z7345d8dc0fc30c62eb06896e10b19afa32724bb53145a5eead8c7c69058186c0
CISACVE-2023-4346CVE-2026-60137CVE-2026-63030DaxinDoSEY breach support tickets','supply chain risk','Nichirei','russ‑Ernst & YoungFortiSandboxFortinetHollowByteKNX ProtocolKnown Exploited VulnerabilitiesMicrosoft SharePointOpenSSLOracleRCEStupigdata breachdenial of serviceremote code executionrootkitthird-party breachwordpresswp2shell

What happened

Multiple high-impact security stories: public exploits were released for two critical WordPress Core flaws (wp2shell) — CVE-2026-63030 and CVE-2026-60137 — that can be chained for pre-auth remote code execution on default installs. Okta disclosed an 11-byte OpenSSL memory-exhaustion DoS named “HollowByte” that allows unauthenticated remote triggers of large allocations. Symantec found the long-lived China-linked Daxin kernel rootkit (with a new Stupig backdoor) on a Taiwanese manufacturer’s network dating back to 2013. CISA added multiple vulnerabilities (including Fortinet FortiSandbox, MS S‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
7345d8dc0fc30c62eb06896e10b19afa32724bb53145a5eead8c7c69058186c0
Enrichment time
2026-07-19T14:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.