Critical wp2shell WordPress flaws exploited to install webshells

Summary

Hackers are actively exploiting critical vulnerabilities in WordPress Core, known as wp2shell (CVE-2026-63030 and CVE-2026-60137), to deploy webshells and install malicious plugins. These exploits allow for persistent access and further compromise of affected servers. The vulnerabilities enable attackers to gain control and execute arbitrary code, leading to a range of malicious activities.

IFF Assessment

FOE

The exploitation of critical vulnerabilities to gain persistent access and install malware is detrimental to the security of WordPress websites and their users.

Severity

9.8 Critical

The described vulnerabilities allow for remote code execution and webshell deployment, enabling attackers to gain significant control over affected servers. This high impact, coupled with likely ease of exploitation due to the critical nature of the flaws, justifies a high CVSS score.

CISA KEV: Listed as actively exploited. Federal patch due: July 24, 2026. Known ransomware use: Unknown.

Defender Context

This critical vulnerability in WordPress Core presents a significant risk to websites globally. Defenders must prioritize patching or implementing mitigating controls immediately to prevent webshell deployment and further compromise. Monitoring for indicators of compromise related to these CVEs is crucial for early detection.

Read Full Story →