Attackers exploit critical WordPress Core wp2shell flaws CVE-2026-63030 and CVE-2026-60137 to install webshells

Hackers are actively breaking into vulnerable WordPress sites and planting backdoors that let them keep control of the server. The 'wp2shell' chain affects WordPress Core and abuses the REST API batch-processing feature to achieve unauthenticated remote code execution using CVE-2026-63030 and CVE-2026-60137. WordPress patched the issue in versions 7.0.2, 6.9.5, and 6.8.6, and researchers observed malicious plugins, rogue admin accounts, and PHP webshells being deployed.
Why it matters: WordPress powers a large share of the public web, so active exploitation creates immediate risk for website owners, businesses, and users of compromised sites. Organizations running WordPress should update immediately, review plugins and admin accounts, and check for webshells or unusual REST API activity.

Sources

Critical wp2shell WordPress flaws exploited to install webshells
Bill Toulas 2026.07.21 100% relevant
This article establishes a distinct tracked story by tying the newly disclosed wp2shell WordPress Core vulnerabilities to real-world exploitation, post-patch attack activity, and concrete indicators of compromise.
← Back to all stories