Hackers are exploiting the “wp2shell” critical vulnerability suite (CVE-2026–63030 and CVE-2026–60137) affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers.
The critical exploit chain abuses the WordPress REST API’s batch-processing feature, allowing remote attackers to execute code on vulnerable installations without the need to authenticate.
Although the technical details were not released, proof-of-concept exploits started to emerge over the weekend, shortly after threat intelligence and cyber risk management company SearchLight Cyber disclosed the wp2shell security issue.
