WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.

The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell.

“By the early hours of Saturday morning (UTC), successful exploitation was already well

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats

AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory

AI Recommendation Poisoning: How “Ask AI” Buttons Silently Alter LLM Memory A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and

AI doesn’t generate working products, that’s still your job

AI doesn’t generate working products, that’s still your job Source: Hacker News