'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

Summary

Attackers are actively exploiting a vulnerability chain, including CVE-2026-60137 and CVE-2026-63030, to target millions of WordPress sites. This vulnerability, dubbed 'WP2Shell', allows for remote takeover of affected sites.

IFF Assessment

FOE

The exploitation of WP2Shell and associated CVEs enables attackers to gain unauthorized remote control over WordPress sites, posing a direct threat to defenders.

Severity

9.8 Critical

The vulnerability allows for remote takeover, indicating a high impact on confidentiality, integrity, and availability. The widespread attack surface of WordPress and the active chaining of exploits suggest high exploitability.

Defender Context

This incident highlights the critical need for immediate patching of WordPress sites, especially those with plugins that may be susceptible to these chained exploits. Defenders should monitor for exploit attempts targeting the mentioned CVEs and ensure robust security configurations are in place.

Read Full Story →