Skip to content
Wiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137). Attackers are deploying persistent webshells on vulnerable servers. Organizations should prioritize patching or applying WAF mitigations. These vulnerabilities comprise a critical pre-authentication remote code execution (RCE) chain in ...
Exploitation in the Wild of wp2shell | Huntaegis