'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
Summary
Attackers are actively exploiting a vulnerability chain, including CVE-2026-60137 and CVE-2026-63030, to target millions of WordPress sites. This vulnerability, dubbed 'WP2Shell', allows for remote takeover of affected sites.
IFF Assessment
The exploitation of WP2Shell and associated CVEs enables attackers to gain unauthorized remote control over WordPress sites, posing a direct threat to defenders.
Severity
The vulnerability allows for remote takeover, indicating a high impact on confidentiality, integrity, and availability. The widespread attack surface of WordPress and the active chaining of exploits suggest high exploitability.
Defender Context
This incident highlights the critical need for immediate patching of WordPress sites, especially those with plugins that may be susceptible to these chained exploits. Defenders should monitor for exploit attempts targeting the mentioned CVEs and ensure robust security configurations are in place.