ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Vulnerabilities

wp2shell WordPress flaws (CVE-2026-60137) used to deploy persistent webshells

Source headline: Critical wp2shell WordPress flaws exploited to install webshells

Threat level Critical
Signal strength 85/100
Source confidence 1 source
Published 3 hours ago

Intelligence Summary

Attackers are exploiting the wp2shell vulnerability suite in WordPress Core to gain long-term footholds. The activity includes installing persistent webshells and adding malicious plugins to compromised sites. The reported issues map to CVE-2026-60137 and CVE-2026-63030, which enable remote exploitation. Once deployed, webshells can provide ongoing command execution and further malware delivery. Site owners should patch WordPress promptly and review for unauthorized plugin and webshell files.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#wordpress #wp2shell #cve-2026-60137 #malicious-plugin #webshell
Original reporting BleepingComputer Critical wp2shell WordPress flaws exploited to install webshells
Open original source