wiz · Crawled Jul 20, 2026

Exploitation in the Wild of wp2shell

11 IoCs
Read original article ↗

AI Summary

A critical pre-authentication remote code execution (RCE) vulnerability chain in WordPress Core, dubbed 'wp2shell' and tracked as CVE-2026-63030 and CVE-2026-60137, is being actively exploited in the wild. The vulnerabilities allow unauthenticated attackers to execute arbitrary code on vulnerable WordPress instances, leading to webshell deployment, user enumeration, and admin panel access. Multiple threat actors have been observed exploiting these flaws, deploying both simple and sophisticated PHP webshells, while mass scanning campaigns suggest widespread opportunistic targeting.

AI-extracted · verify before operational use

Indicators of Compromise 11 extracted

Type Value Detail
SHA-1 2a1410d8e2a8337ac2171cedea8c0fdc47c647a0 Details →
SHA-1 58eca847e9eae9e6b08cc211f1559817b71bc4cc Details →
SHA-1 ebea44890f434d5d67ede22009a3f4bb5cac33f8 Details →
SHA-1 d9a220c8039f1c4d72cae7ccb8b3a33dec8815be Details →
SHA-1 e9756e2338f84746007235e4cab7a70d5b3ca47f Details →
IP 45[.]79[.]167[.]238 Details →
IP 34[.]81[.]132[.]62 Details →
IP 79[.]177[.]131[.]206 Details →
IP 15[.]157[.]135[.]170 Details →
IP 94[.]100[.]52[.]128 Details →
IP 172[.]235[.]128[.]52 Details →