Back to Feed
VulnerabilitiesJul 20, 2026

'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

WP2Shell vulnerability allows remote takeover of millions of WordPress sites.

Vendor Watch

Run WordPress?

Get an email when a reviewed story names WordPress, usually within the hour.

Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch worksPrivacy

Summary

Attackers are actively exploiting two vulnerabilities, CVE-2026-60137 and CVE-2026-63030, to gain remote control of millions of WordPress websites. This widespread exploitation began shortly after the vulnerabilities were disclosed, targeting one of the internet's largest attack surfaces.

Indicators of Compromise

  • cve — CVE-2026-63030
  • cve — CVE-2026-60137

Entities

WordPress (product)