Cybersecurity · 29 views
Critical wp2shell WordPress flaws exploited to install webshells
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers.
Summary
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers. The critical exploit chain abuses the WordPress REST API’s batch-processing feature, allowing remote attackers to execute code on vulnerable installations without the need to authenticate.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedCoverage Context
More from Cybersecurity
Continue reading recent Cybersecurity coverage
- Gyazo server flaw exploited to steal 23.6 million user recordsContinue reading
- Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2Continue reading
- Fake LastPass Authenticator GitHub repos push new Rapuncel infostealerContinue reading
- In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow