wiz · Crawled Jul 21, 2026

300 WINtegrations Strong: An Open Security Ecosystem Built for the Speed of AI

Read original article ↗

AI Summary

Wiz Research has identified active exploitation of a critical pre-authentication remote code execution vulnerability chain in WordPress Core, referred to as 'wp2shell'. The vulnerabilities, tracked as CVE-2026-63030 and CVE-2026-60137, are being exploited in the wild to deploy persistent webshells on unpatched servers. Organizations are urged to prioritize patching or implement WAF-based mitigations to prevent compromise.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.