Critical wp2shell WordPress flaws exploited to install webshells | HappeningNow.news

Cybersecurity · 29 views

Critical wp2shell WordPress flaws exploited to install webshells

Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers.

Source Summary Published July 21, 2026 Brief Under 1 min brief
Story intelligence
Coverage Single outlet Single-outlet story
Views 29 Community interest
Brief read Under 1 min brief 50 words

Summary

Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. The critical exploit chain abuses the WordPress REST API’s batch-processing feature, allowing remote attackers to execute code on vulnerable installations without the need to authenticate.

Read original at Bleepingcomputer

Coverage Context

Part of Wordpress coverage 61 tracked stories

More from Cybersecurity

Continue reading recent Cybersecurity coverage

Support HappeningNow

Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.

Support HappeningNow

Report an issue with this page