Critical wp2shell WordPress flaws exploited to install webshells
Summary
Hackers are actively exploiting critical vulnerabilities in WordPress Core, known as wp2shell (CVE-2026-63030 and CVE-2026-60137), to deploy webshells and install malicious plugins. These exploits allow for persistent access and further compromise of affected servers. The vulnerabilities enable attackers to gain control and execute arbitrary code, leading to a range of malicious activities.
IFF Assessment
The exploitation of critical vulnerabilities to gain persistent access and install malware is detrimental to the security of WordPress websites and their users.
Severity
The described vulnerabilities allow for remote code execution and webshell deployment, enabling attackers to gain significant control over affected servers. This high impact, coupled with likely ease of exploitation due to the critical nature of the flaws, justifies a high CVSS score.
CISA KEV: Listed as actively exploited. Federal patch due: July 24, 2026. Known ransomware use: Unknown.
Defender Context
This critical vulnerability in WordPress Core presents a significant risk to websites globally. Defenders must prioritize patching or implementing mitigating controls immediately to prevent webshell deployment and further compromise. Monitoring for indicators of compromise related to these CVEs is crucial for early detection.