Critical wp2shell WordPress flaws exploited to install webshells
Hackers are actively exploiting two critical vulnerabilities in WordPress Core, tracked as CVE-2026-63030 and CVE-2026-60137, collectively known as "wp2shell." These flaws allow attackers to deploy persistent webshells and install malicious plugins on affected sites. The vulnerabilities affect millions of WordPress installations globally, with proof-of-concept exploits publicly available. Security researchers have observed a spike in attacks targeting unpatched sites, particularly those running older versions of WordPress. The WordPress security team has released emergency patches, urging all site administrators to update immediately. The attacks are believed to be automated, scanning for vulnerable sites at scale.
Global Impact
This is a significant cybersecurity event affecting the largest content management system on the web, with over 40% of all websites running WordPress. The economic impact includes remediation costs for millions of site owners, potential data breach liabilities, and reputational damage for affected businesses.
Why this score
Neat Digest rated this story 4.9/10 — Standard tier.
Significant tier: widespread vulnerability affecting millions of sites with active exploitation and public PoCs, but not civilization-ending or era-defining; comparable to a major software supply chain event.
Sources on this story
Reported by 1 sources, including:
- BleepingComputer