216.73.217.24

Exploitation in the Wild of wp2shell

· Published 23/07/2026 09:30

Export JSON

Essential information

Published
23/07/2026 09:30
Modified
Source / Author
AlienVault
Confidence
100/100
Report type(s)
threat-report
Labels / Tags
batch api exploitation cmsmap cve-2026-60137 cve-2026-63030 plugin upload pre-authentication rce sql injection webshell wordpress
Related entities
2 vulnerabilities (cve), 3 indicators, 3 observables, 16 techniques (mitre), 1 malware

Description

A critical pre-authentication remote code execution vulnerability chain dubbed "wp2shell" affecting Core has been actively exploited in the wild. The vulnerability chain, consisting of CVE-2026-63030 and CVE-2026-60137, allows unauthenticated attackers to gain remote code execution on default installations. Multiple threat actors have been observed exploiting these vulnerabilities almost immediately after public disclosure, deploying persistent webshells and backdoors through malicious plugin uploads. Post-exploitation activities include user enumeration, local file inclusion attempts, and admin panel access. Three distinct PHP webshells have been identified, ranging from simple one-liners to sophisticated 150KB attack platforms disguised as legitimate plugins. Organizations should prioritize patching or implementing WAF mitigations to block access to Batch API endpoints.

External references