Critical wp2shell WordPress flaws exploited to install webshells

Critical wp2shell WordPress flaws exploited to install webshells
Hackers are actively exploiting the WordPress Core “wp2shell” vulnerability suite, using unauthenticated REST API abuse to deploy persistent webshells, malicious plugins, and rogue administrator accounts. WordPress has released patched versions and forced automatic updates, while researchers continue to track ongoing attack activity and live patching rates. #wp2shell #WordPressCore #SearchLightCyber #Wiz #Defiant #SansTechnologyInstitute #CMSmap

Keypoints

  • Attackers are exploiting wp2shell CVE-2026-63030 and CVE-2026-60137 in WordPress Core.
  • The exploit chain abuses the WordPress REST API batch-processing feature without authentication.
  • Threat actors are installing malicious plugins and persistent PHP webshells on vulnerable sites.
  • Some attacks also attempt local file inclusion, admin panel access, and rogue administrator creation.
  • Administrators should patch immediately, review logs, inspect plugins, and check for suspicious PHP files.

Read More: https://www.bleepingcomputer.com/news/security/critical-wp2shell-wordpress-flaws-exploited-to-install-webshells/