Skip to content
The Nexus
DossierENTITY

CVE-2026-60137

Coverage of CVE-2026-60137 in the Nexus archive.

Earliest in view: Jul 20 · 21:38 UTCMost recent: Jul 21 · 08:59 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYJul 21 · 08:59 UTCTHE HACKER NEWS
    WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

    Attackers are exploiting two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, codenamed wp2shell, to achieve unauthenticated remote code execution and fully compromise vulnerable websites. The exploitation has led to increased mass scanning of WordPress sites.

  • SECURITYJul 20 · 21:57 UTCTHE REGISTER
    Attackers pummel critical WordPress vuln to create all sorts of mischief

    Attackers are exploiting two critical WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) to enable pre-authentication remote code execution. The flaws, patched in WordPress versions 6.9.5 and 7.1 Beta 2, allow unauthenticated users to execute arbitrary code by chaining an SQL injection issue with a REST API route confusion bug. Security researchers observed widespread exploitation within hours of the patches being released.

  • SECURITYJul 20 · 21:38 UTCDARK READING
    'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

    A new vulnerability called 'WP2Shell' has been discovered in WordPress, allowing remote takeover. Attackers are actively exploiting CVE-2026-60137 and CVE-2026-63030 to target millions of sites.

CVE-2026-60137 · Dossier · The Nexus