bleeping-computer · Crawled Jul 21, 2026

Critical wp2shell WordPress flaws exploited to install webshells

3 IoCs
Read original article ↗

AI Summary

Hackers are actively exploiting the 'wp2shell' vulnerability suite (CVE-2026-63030 and CVE-2026-60137) in WordPress Core to deploy webshells and install malicious plugins without authentication. The attacks leverage the WordPress REST API's batch-processing feature to execute remote code and establish persistent access. Threat actors are scanning for vulnerable sites, uploading malicious plugins, installing obfuscated PHP webshells, and harvesting admin credentials, with some creating rogue administrator accounts.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
Domain admin-ajax[.]php Details →
Filename CMSmap Details →
Filename wp-config Details →