WordPress wp2shell: the exploit chain fueling mass scanning
Two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, have been combined into the chain known as wp2shell, capable of going from an unauthenticated request all the way to full site compromise. After the patch was published, attackers began mass scanning and exploiting the flaw within hours, turning the fix into a roadmap for exploitation. Researchers’ reports show that many groups initially limit themselves to reconnaissance, but some also try to extract data, credentials, or gain persistent control. The case is a very clear example of the N-day phenomenon becoming almost immediately N-hour. For WordPress site operators, the message is simple: updating is not enough; they must also check for any compromises that may already have occurred.
Sources
- WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning — The Hacker News
- Three days of wp2shell exploitation, from the perspective of a honeynet — threat intelligence


Leave a Reply