WP2Shell WordPress Vulnerabilities Exploited in the Wild
Summary
Exploitation of two newly disclosed WordPress vulnerabilities, CVE-2026-60137 and CVE-2026-63030, began shortly after their public announcement. These vulnerabilities are being actively leveraged in the wild.
IFF Assessment
FOE
The exploitation of WordPress vulnerabilities in the wild poses a direct threat to the security of websites and their users.
Severity
9.8
Critical
Defender Context
Defenders should prioritize patching or mitigating these WP2Shell vulnerabilities in their WordPress deployments. The immediate exploitation in the wild underscores the urgency to apply security updates and monitor for any suspicious activity targeting WordPress sites.