WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.

The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell.

“By the early hours of Saturday morning (UTC), successful exploitation was already well

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure

Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint

The tragedy of the commons, AI edition

The tragedy of the commons, AI edition Source: Hacker News

GitHub ‘Verified’ Commits Can Be Rewritten Into New Hashes Without Breaking Signatures

GitHub ‘Verified’ Commits Can Be Rewritten Into New Hashes Without Breaking Signatures New research shows that a signed Git commit’s hash is not the one-of-a-kind name that much of the