Attackers actively exploit two critical WordPress vulnerabilities in coordinated campaigns, leveraging public exploit code to target thousands of websites. The flaws, CVE-2026-63030 and CVE-2026-60137, combine to deliver unauthenticated remote code execution and full site compromise. Security researchers designated the attack chain wp2shell.
Public disclosure of working exploits triggered immediate mass scanning activity. By early Saturday UTC, successful compromises were already documented across vulnerable installations. The vulnerabilities allow attackers to bypass WordPress authentication entirely, meaning patched or unpatched status becomes irrelevant if both flaws exist on a target system.
The wp2shell attack chain reflects a pattern where proof-of-concept code accelerates exploitation timelines dramatically. Attackers typically scan for vulnerable versions within hours of public exploit release. Organizations running affected WordPress versions face urgent patching requirements.
WordPress site operators should treat these vulnerabilities as critical. The RCE capability enables attackers to install backdoors, harvest sensitive data, inject malicious content, or pivot to internal networks if the WordPress installation connects to other systems. Hosting providers reported increased compromise attempts targeting customer installations.
Remediation requires applying vendor patches to both CVEs. Site administrators should verify patch status immediately through WordPress core update mechanisms. Those unable to patch immediately should consider taking affected sites offline, implementing Web Application Firewall rules to block exploitation attempts, or restricting administrative access to known IP ranges.
The vulnerability chain demonstrates why WordPress security remains a persistent industry challenge. With millions of WordPress sites worldwide, even incremental exploitation rates result in thousands of compromised assets. Public exploit availability compresses the window between disclosure and widespread attacks from days to hours.
Organizations hosting WordPress should monitor update channels actively and deploy patches within 24 hours of release for critical vulnerabilities. Consider implementing vulnerability scanning tools to identify unpatched installations before attackers do.
CATEGORY
