www.darkreading.com 7/20/2026, 10:01:41 PM · external

'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
Developing story malware 10 articles tracked
WordPress core flaws CVE-2026-60137 and CVE-2026-63030 exploited in the wild
CyberSIXT Evidence Panel
Primary Source wordpress.org
CISA KEV Not in KEV
Patch Patch Status Unknown

THE article discusses the recent exploitation of two critical vulnerabilities in WordPress, identified as CVE-2026-60137 and CVE-2026-63030, which allow unauthenticated remote code execution on millions of sites. Discovered using AI technology, these flaws affect WordPress versions 6.9.0 - 6.9.4 and 7.0.0 - 7.0.1. The vulnerabilities can be exploited in a chained manner, enabling attackers to bypass security checks.

Organizations are urged to update to the latest WordPress version to prevent potential compromises as exploitation attempts have surged substantially, creating backdoor accounts and deploying malicious plugins. The situation highlights the risks posed by AI in vulnerability exploitation and the need for vigilant security measures by users.

View Primary Source Via www.darkreading.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline