WP2Shell WordPress Vulnerabilities Exploited in the Wild
Summary
Exploitation of two newly disclosed WordPress vulnerabilities, CVE-2026-60137 and CVE-2026-63030, began shortly after their public announcement. These vulnerabilities are being actively leveraged in the wild.
IFF Assessment
The exploitation of WordPress vulnerabilities in the wild poses a direct threat to the security of websites and their users.
Severity
Given that these are critical WordPress vulnerabilities being actively exploited, a high CVSS score is estimated. This reflects a high attack vector, significant impact on confidentiality, integrity, and availability, and likely high exploitability.
Defender Context
Defenders should prioritize patching or mitigating these WP2Shell vulnerabilities in their WordPress deployments. The immediate exploitation in the wild underscores the urgency to apply security updates and monitor for any suspicious activity targeting WordPress sites.