WP2Shell WordPress Vulnerabilities Exploited in the Wild

WP2Shell WordPress Vulnerabilities Exploited in the Wild
Two newly patched WordPress flaws, tracked as CVE-2026-60137 and CVE-2026-63030, are being actively exploited in the wild soon after disclosure. Chaining WP2Shell enables unauthenticated remote code execution on affected WordPress sites, prompting forced updates and protective rules from WordPress and Cloudflare. #WP2Shell #CVE-2026-60137 #CVE-2026-63030 #WordPress #Cloudflare

Keypoints

  • WP2Shell includes CVE-2026-60137 and CVE-2026-63030.
  • The flaws affect WordPress 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1.
  • Attackers can exploit a stock WordPress install with no plugins.
  • Chaining the bugs enables unauthenticated remote code execution.
  • WordPress and Cloudflare released fixes and detection rules.

Read More: https://www.securityweek.com/wp2shell-wordpress-vulnerabilities-exploited-in-the-wild/