Exploitation in the Wild of wp2shell
Essential information
- Published
- 23/07/2026 09:30
- Modified
- —
- Source / Author
- AlienVault
- Confidence
- 100/100
- Report type(s)
- threat-report
- Labels / Tags
- batch api exploitation cmsmap cve-2026-60137 cve-2026-63030 plugin upload pre-authentication rce sql injection webshell wordpress
- Related entities
- 2 vulnerabilities (cve), 3 indicators, 3 observables, 16 techniques (mitre), 1 malware
Description
A critical pre-authentication remote code execution vulnerability chain dubbed "wp2shell" affecting WordPress Core has been actively exploited in the wild. The vulnerability chain, consisting of CVE-2026-63030 and CVE-2026-60137, allows unauthenticated attackers to gain remote code execution on default WordPress installations. Multiple threat actors have been observed exploiting these vulnerabilities almost immediately after public disclosure, deploying persistent webshells and backdoors through malicious plugin uploads. Post-exploitation activities include user enumeration, local file inclusion attempts, and admin panel access. Three distinct PHP webshells have been identified, ranging from simple one-liners to sophisticated 150KB attack platforms disguised as legitimate WordPress plugins. Organizations should prioritize patching or implementing WAF mitigations to block access to WordPress Batch API endpoints.