Exploitation in the Wild of wp2shell
CYBERSECURITY FEATURED ANALYSIS

Exploitation in the Wild of wp2shell

BY

Gili Tikochinski

SOURCE

Wiz Blog | RSS feed

DATE

READ

1 min read

Wiz Research has identified exploitation of “wp2shell”, a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137). Attackers are deploying persistent webshells …

Wiz Research has identified exploitation of “wp2shell”, a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137). Attackers are deploying persistent webshells on vulnerable servers. Organizations should prioritize patching or applying WAF mitigations.