Hackers are exploiting the ‘wp2shell’ crucial vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress core to deploy a persistent net shell and set up malicious plugins on affected servers.
This vital exploit chain exploits the batch processing performance of the WordPress REST API, permitting distant attackers to execute code on susceptible installations with out requiring authentication.
Though technical particulars haven’t been made public, proof-of-concept exploits started to emerge over the weekend shortly after risk intelligence and cyber danger administration agency SearchLight Cyber disclosed safety points with wp2shell.
An energetic exploit was rapidly recognized after WordPress addressed the problem in variations 7.0.2, 6.9.5, and 6.8.6 and compelled computerized safety updates for supported installations.
Cloud safety firm Wiz shared technical particulars about an noticed assault leveraging wp2shell, stating that the risk actor carried out the next actions:
- Bulk scan susceptible WordPress installations (most of that are safety scans).
- Abuses the add performance of WordPress plugins to put in malicious add-ons.
- Putting in PHP net shells, from easy one-liner backdoors to feature-rich obfuscated shells disguised as plugins (CMSmap).
- Acquire the administrator username and e-mail handle by querying the WordPress REST API.
- Native file inclusion makes an attempt to focus on wp-config by means of admin-ajax.php to retrieve database credentials and authentication keys.
- Introducing a malicious plugin that exposes a REST API endpoint for distant command execution
- You’ve got efficiently accessed your WordPress admin panel.
Wiz mentioned it has not noticed any lateral motion or knowledge leaks, however continues to observe risk exercise.

Supply: Wiz
One other report on energetic wp2shell exploitation by Johannes B. Ullrich, Director of Analysis at Sans Know-how Insitute, describes a two-step assault that begins by probing the PHP WebShell for SQL injection for vulnerabilities earlier than delivering it to the server.
An internet shell was created beneath. /wp-content/cache/ A listing with randomized filenames that can be used as a password for entry through a variable in a URL request. In any other case, the web page returns a faux 404 web page.
The online shell code printed by Ullrich checked the provision of a number of PHP features. system(), passthrough(), execution(), shell_exec(), Popen()or utilizing the backtick operator to attempt to run the command.
Some assaults additionally contain creating fraudulent administrator accounts, Ullrich mentioned. Subsequently, researchers suggest checking the /cache/ listing and searching for newly created customers.
WordPress safety agency Defiant additionally printed an “aftermath” submit stating that an preliminary exploit-related investigation was noticed on July 17 at 23:29 UTC, adopted by an obvious SQL injection try simply 13 minutes later.
Directors of WordPress websites ought to instantly replace to the patched model, examine logs for wp2shell-related requests, examine put in plugins, and examine for malicious PHP file additions or newly created administrator accounts.
Macnica researcher Yutaka Sechiyama has created a dashboard that can assist you monitor patch charges dwell. The portal reviews a patch charge of 81.6% out of a pattern of 124,580 web sites evaluated.
Yesterday, SearchLight Cyber researcher Adam Kues printed a follow-up report that takes a deep dive into the method of discovering wp2shell and growing a working exploit chain, together with using AI instruments.
Safety groups doc 54% of profitable assaults and challenge a warning on solely 14%. The remainder strikes invisibly by means of the atmosphere.
Picus’ whitepaper exhibits the best way to check your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
