WP2Shell WordPress vulnerabilities (CVE-2026-60137) being exploited in the wild
Source headline: WP2Shell WordPress Vulnerabilities Exploited in the Wild
Intelligence Summary
Recent WordPress vulnerabilities are already being exploited in real-world attacks. Exploitation activity follows disclosure of CVE-2026-60137 and CVE-2026-63030. The malicious use of these flaws suggests an active threat actor workflow rather than proof-of-concept testing. WordPress site owners are at risk of compromise depending on patch status and exposure. Users should confirm they are running fixed versions and review web application logs for suspicious requests. If you cannot patch immediately, mitigate exposure by restricting public access and hardening WordPress endpoints.
Recommended Action
Review affected assets, schedule urgent remediation, and monitor related indicators.