Exploitation in the Wild of wp2shell
wiz.io | blog | #rce | #wordpress | #vulnerability | #webshell | #cve-2026-63030 | #cve-2026-60137 | #exploit-in-the-wild
Summary
Wiz Research observed in-the-wild exploitation of wp2shell, a pre-auth RCE chain in WordPress Core (CVE-2026-63030, CVE-2026-60137), used to install persistent webshells and backdoor plugins.
- Published
- Collected
Skip to content