Skip to content
The Nexus
SECURITYJul 20 · 21:38 UTCDARK READINGJai Vijayan

'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

A new vulnerability called 'WP2Shell' has been discovered in WordPress, allowing remote takeover. Attackers are actively exploiting CVE-2026-60137 and CVE-2026-63030 to target millions of sites.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting