256 Newsroom — Uganda's Digital News Infrastructure
Consumer Technology

Critical wp2shell WordPress flaws exploited to install webshells - BleepingComputer

Share
Critical wp2shell WordPress flaws exploited to install webshells - BleepingComputer
Image · BleepingComputer

What the report says

BleepingComputer reported that attackers are actively exploiting a critical WordPress Core vulnerability chain known as “wp2shell,” tracked as CVE-2026-63030 and CVE-2026-60137, to place persistent webshells and malicious plugins on affected sites. The article, published July 21, said the exploit chain targets the WordPress REST API batch-processing feature and can allow unauthenticated remote code execution on vulnerable installations.

According to the report, proof-of-concept exploit code began appearing after SearchLight Cyber disclosed the issue, and exploitation was confirmed soon after WordPress released fixes in versions 7.0.2, 6.9.5 and 6.8.6. BleepingComputer said automatic security updates were pushed for supported installations. Cloud security company Wiz described activity including broad scanning, malicious plugin uploads, REST API queries to gather administrator details, attempts to access wp-config data, and deployment of a plugin that exposes a remote command execution endpoint. Wiz said it had not seen lateral movement or data theft in the activity it observed.

The report also cited Johannes B. Ullrich of the SANS Technology Institute, who described attacks that probe for the flaw before delivering a PHP webshell under the /wp-content/cache/ directory, sometimes using randomized filenames and fake 404 responses to hide access. Ullrich also reported some cases involving rogue administrator accounts.

Site administrators were urged to apply the patched WordPress versions immediately, review logs for suspicious wp2shell-related requests, inspect installed plugins, and check for new PHP files or unexpected administrator users. BleepingComputer also noted that a public patch-tracking dashboard by Macnica researcher Yutaka Sejiyama showed an 81.6% patch rate among 124,580 sampled websites at the time referenced.

Read the full report at BleepingComputer →

Loading debate for this article…

Other publishers covering this story

No additional verified coverage is currently clustered with this report.

Related reporting