Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
wp2shell Vulnerability Exploitation Escalates

wp2shell Vulnerability Exploitation Escalates

Posted on July 21, 2026 By CWS

Two significant security vulnerabilities in WordPress, collectively known as wp2shell, are being actively exploited by attackers. These issues allow unauthenticated remote code execution, posing a major risk to any website running a vulnerable version of WordPress.

Detailing the wp2shell Vulnerabilities

The vulnerabilities, identified as CVE-2026-63030 and CVE-2026-60137, are critical. Exploitation began swiftly after public exploit code surfaced, enabling attackers to extract hashed credentials. Jake Knott, a principal security researcher at watchTowr, highlighted the widespread impact of these flaws across various organizations.

Telemetry from KEVIntel identified 13 IP addresses across several countries, including Switzerland and Germany, as being involved in exploiting CVE-2026-63030. This flaw, discovered with the help of OpenAI’s GPT 5.6 Sol, affects default WordPress setups without additional plugins.

Understanding the Exploitation Process

Searchlight Cyber noted that the wp2shell exploit chain begins with unauthenticated SQL injection via CVE-2026-60137. This issue affects WordPress installations from version 6.8 onward, while the remote code execution vulnerability impacts version 6.9 and beyond.

Cloudflare explained that the RCE exploit is possible only when persistent object caching is not implemented. The SQL injection vulnerability stems from improper sanitization of certain parameters, which can lead to unauthorized access or data manipulation.

Consequences and Protective Measures

Data from Wiz, a Google-owned firm, indicated that 60% of organizations were initially vulnerable to these exploits. However, this figure is decreasing as more organizations apply necessary patches. Post-exploitation activities observed include uploading malicious plugins, accessing admin panels, and executing local file inclusion attacks.

WatchTowr reported that attackers are engaging in indiscriminate scanning following the release of the exploit, with tens of thousands of attempts recorded. Over 100 backdoor admin accounts have been created, facilitating further exploitation.

Organizations are advised to scrutinize their WordPress setups for any unauthorized admin accounts or suspicious plugins. Even if patches are applied, thorough checks are crucial to ensure complete elimination of the threat.

The Hacker News Tags:CVE-2026-60137, CVE-2026-63030, cyber attacks, Cybersecurity, remote code execution, security flaws, SQL injection, Vulnerabilities, WordPress, wp2shell

Post navigation

Previous Post: Addressing Identity Fragmentation in Cybersecurity
Next Post: ServiceNow Vulnerability Exploited Post-Disclosure

Related Posts

U.S. Arrests Key Facilitator in North Korean IT Worker Scheme, Seizes .74 Million U.S. Arrests Key Facilitator in North Korean IT Worker Scheme, Seizes $7.74 Million The Hacker News
China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services China-Linked APT31 Launches Stealthy Cyberattacks on Russian IT Using Cloud Services The Hacker News
Trojanized Gaming Tools Spread Java RAT via Online Platforms Trojanized Gaming Tools Spread Java RAT via Online Platforms The Hacker News
CISA Flags SolarWinds Vulnerability in Security Alert CISA Flags SolarWinds Vulnerability in Security Alert The Hacker News
Turning Disruptive Technology into a Strategic Advantage Turning Disruptive Technology into a Strategic Advantage The Hacker News
Google Warns Salesloft OAuth Breach Extends Beyond Salesforce, Impacting All Integrations Google Warns Salesloft OAuth Breach Extends Beyond Salesforce, Impacting All Integrations The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft to End Copilot Podcasts in 2026
  • Empirical Secures $25M for AI Cybersecurity Expansion
  • Android AI Agents Vulnerable to Covert Code Execution
  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft to End Copilot Podcasts in 2026
  • Empirical Secures $25M for AI Cybersecurity Expansion
  • Android AI Agents Vulnerable to Covert Code Execution
  • Microsoft Defender XDR Vulnerability in Network Detection
  • HollowGraph Malware Exploits Microsoft 365 Calendar for C&C

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark