Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Exploitation in the Wild of wp2shell

Summary

Wiz Research observed in-the-wild exploitation of wp2shell, a pre-auth RCE chain in WordPress Core (CVE-2026-63030, CVE-2026-60137), used to install persistent webshells and backdoor plugins.
Published
Collected

original ↗

Related coverage

back