Dossier
unauthenticated remote code execution
Coverage of unauthenticated remote code execution in the Nexus archive.
- WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers are exploiting two critical WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137, codenamed wp2shell, to achieve unauthenticated remote code execution and fully compromise vulnerable websites. The exploitation has led to increased mass scanning of WordPress sites.