wiz · Crawled Jul 20, 2026
Exploitation in the Wild of wp2shell
11 IoCs
Read original article ↗
AI Summary
A critical pre-authentication remote code execution (RCE) vulnerability chain in WordPress Core, dubbed 'wp2shell' and tracked as CVE-2026-63030 and CVE-2026-60137, is being actively exploited in the wild. The vulnerabilities allow unauthenticated attackers to execute arbitrary code on vulnerable WordPress instances, leading to webshell deployment, user enumeration, and admin panel access. Multiple threat actors have been observed exploiting these flaws, deploying both simple and sophisticated PHP webshells, while mass scanning campaigns suggest widespread opportunistic targeting.
AI-extracted · verify before operational use
Indicators of Compromise 11 extracted
| Type | Value | Detail |
|---|---|---|
| SHA-1 | 2a1410d8e2a8337ac2171cedea8c0fdc47c647a0 | Details → |
| SHA-1 | 58eca847e9eae9e6b08cc211f1559817b71bc4cc | Details → |
| SHA-1 | ebea44890f434d5d67ede22009a3f4bb5cac33f8 | Details → |
| SHA-1 | d9a220c8039f1c4d72cae7ccb8b3a33dec8815be | Details → |
| SHA-1 | e9756e2338f84746007235e4cab7a70d5b3ca47f | Details → |
| IP | 45[.]79[.]167[.]238 | Details → |
| IP | 34[.]81[.]132[.]62 | Details → |
| IP | 79[.]177[.]131[.]206 | Details → |
| IP | 15[.]157[.]135[.]170 | Details → |
| IP | 94[.]100[.]52[.]128 | Details → |
| IP | 172[.]235[.]128[.]52 | Details → |