WP2Shell WordPress Vulnerabilities Exploited in the Wild

Summary

Exploitation of two newly disclosed WordPress vulnerabilities, CVE-2026-60137 and CVE-2026-63030, began shortly after their public announcement. These vulnerabilities are being actively leveraged in the wild.

IFF Assessment

FOE

The exploitation of WordPress vulnerabilities in the wild poses a direct threat to the security of websites and their users.

Severity

9.8 Critical

Given that these are critical WordPress vulnerabilities being actively exploited, a high CVSS score is estimated. This reflects a high attack vector, significant impact on confidentiality, integrity, and availability, and likely high exploitability.

Defender Context

Defenders should prioritize patching or mitigating these WP2Shell vulnerabilities in their WordPress deployments. The immediate exploitation in the wild underscores the urgency to apply security updates and monitor for any suspicious activity targeting WordPress sites.

Read Full Story →