SECURITYDARK READING
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
A new vulnerability called 'WP2Shell' has been discovered in WordPress, allowing remote takeover. Attackers are actively exploiting CVE-2026-60137 and CVE-2026-63030 to target millions of sites.
Related Signal
Adjacent reporting
- WordPress Core "wp2shell" RCE flaws get public exploits, patch now
- New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
- Critical Everest Forms Pro flaw exploited to take over WordPress sites
- Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks
- Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites