wp2shell RCE in WordPress: CVE-2026-63030 and CVE-2026-60137 exploitation
Source headline: WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Intelligence Summary
Attackers are combining two WordPress flaws to achieve unauthenticated remote code execution. The vulnerabilities are tracked as CVE-2026-63030 and CVE-2026-60137 and are known under the wp2shell theme. Public exploit techniques appear to be enabling widespread automated scanning of exposed sites. Successful chains can lead to full compromise rather than limited impact. WordPress administrators should check for affected versions and apply vendor fixes or mitigations as soon as possible.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.