Recent findings reveal that attackers are actively exploiting two newly discovered vulnerabilities in WordPress, identified as CVE-2026-63030 and CVE-2026-60137, collectively referred to as wp2shell. These vulnerabilities enable unauthenticated remote code execution (RCE), which poses a severe risk of full website compromise. Reports indicate that exploitation efforts surged shortly after public disclosure, underscoring the urgency for site administrators to address these vulnerabilities promptly.
For businesses utilizing WordPress, the implications are significant. Organizations must prioritize immediate patching of the affected versions to prevent unauthorized access and potential data breaches. This situation highlights the critical need for robust cybersecurity practices, including regular updates, vulnerability assessments, and monitoring for unusual activities. As attackers increasingly leverage public exploits for mass scanning, this incident serves as a stark reminder of the evolving threat landscape in cybersecurity and the importance of proactive defenses in safeguarding digital assets.
---
*Originally reported by [The Hacker News](https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html)*