WP2Shell WordPress Vulnerabilities Exploited in the Wild

2026-07-20T07:24:06Z37b209685d8d24ec59b5b8e98e2d224b473de3b2b5ab1fd765c0691671725b36
data-breachexploitation-in-the-wildincident-responsemacosransomwaresecurity-newssharepointwordpresswp2shell

What happened

SecurityWeek reports active exploitation of two WP2Shell WordPress vulnerabilities (CVE-2026-60137 and CVE-2026-63030) soon after disclosure. The feed also highlights a separately disclosed critical SharePoint RCE being exploited in the wild, multiple ransomware incidents (including disruptions at Nichirei, TKMS, and Coca‑Cola/Fairlife), macOS CrashStealer malware, an Iran tracking report, and a Lidl data breach, among other security and funding news.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
37b209685d8d24ec59b5b8e98e2d224b473de3b2b5ab1fd765c0691671725b36
Enrichment time
2026-07-20T07:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.