Skip to main content
CyberConfirmedHighDevelopingFeatured
10.0

Active exploitation of critical WordPress wp2shell vulnerabilities detected

Threat actors are actively exploiting two critical vulnerabilities, CVE-2026-63030 and CVE-2026-60137, in WordPress Core to deploy persistent webshells and malicious plugins. The scope of the compromise and the specific threat actor attribution remain uncertain, posing a significant risk to server integrity across the WordPress ecosystem.

BleepingComputer1 day agoCredibility 54%View source

Score Breakdown

Mosaic Score10.0
Confidence0.9
Significance0.8
Source credibility0.5
Source

Related signals

8 found