256 Newsroom — Uganda's Digital News Infrastructure
Consumer Technology

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning - The Hacker News

Share
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning - The Hacker News
Image · Internet

What the report says

The Hacker News reported on July 21, 2026, that attackers are actively exploiting a pair of critical WordPress vulnerabilities, identified as CVE-2026-63030 and CVE-2026-60137 and collectively dubbed “wp2shell.” According to the report, the flaws can be chained to achieve unauthenticated remote code execution against vulnerable WordPress sites, allowing attackers to take over affected installations without logging in.

The article cited researchers from watchTowr, KEVIntel, Searchlight Cyber, Cloudflare, Intruder and Wiz. WatchTowr said exploitation began after public exploit details appeared, first being used to pull hashed credentials and later to enable code execution. KEVIntel said activity expanded from WordPress-focused probes to broader internet scanning, with exploitation traffic linked to IP addresses in several countries and matching public proof-of-concept patterns.

The reported attack activity includes creation of backdoor administrator accounts, installation of fake or malicious WordPress plugins, deployment of PHP web shells, user enumeration, local file inclusion attempts targeting database credentials and authentication keys, and at least one attempted installation of the Overlord remote access trojan. Wiz said it had observed large-scale scanning alongside post-exploitation behavior, but had not yet confirmed lateral movement or data theft in the activity it reviewed.

The Hacker News said defenders are being urged to patch and then check for compromise rather than assuming updates alone remove the risk. Recommended checks include reviewing newly created administrator accounts, unfamiliar plugins, web shells and suspicious files. The report noted that automatic WordPress security updates and web application firewall rules may have reduced exposure for some sites, while installations with failed or disabled updates may remain at risk.

Read the full report at Internet →

Loading debate for this article…

Other publishers covering this story

No additional verified coverage is currently clustered with this report.

Related reporting