hacker-news · Crawled Jul 21, 2026

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

13 IoCs
Read original article ↗

AI Summary

Attackers are actively exploiting two critical vulnerabilities in WordPress, collectively dubbed wp2shell, to achieve unauthenticated remote code execution on vulnerable sites. The exploit chain combines CVE-2026-63030 and CVE-2026-60137, enabling attackers to bypass authentication and execute arbitrary code via a single HTTP request. Post-exploitation activities include uploading malicious plugins, creating backdoor administrator accounts, deploying web shells, and attempting to install the Overlord RAT. Mass scanning is ongoing, with widespread exploitation observed globally.

AI-extracted · verify before operational use

Indicators of Compromise 13 extracted

Type Value Detail
IP 185[.]18[.]53[.]10 Details →
IP 45[.]146[.]167[.]230 Details →
IP 193[.]18[.]212[.]178 Details →
IP 185[.]220[.]101[.]14 Details →
IP 185[.]220[.]101[.]15 Details →
IP 185[.]220[.]101[.]16 Details →
IP 185[.]220[.]101[.]17 Details →
IP 185[.]220[.]101[.]18 Details →
IP 185[.]220[.]101[.]19 Details →
IP 185[.]220[.]101[.]20 Details →
IP 185[.]220[.]101[.]21 Details →
IP 185[.]220[.]101[.]22 Details →
IP 185[.]220[.]101[.]23 Details →