VulnerabilitiesJul 20, 2026
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
WP2Shell vulnerability allows remote takeover of millions of WordPress sites.
Vendor Watch
Run WordPress?
Get an email when a reviewed story names WordPress, usually within the hour.
Free. Your list stays private and never appears in a subject line. One click stops it. How Vendor Watch worksPrivacy
Summary
Attackers are actively exploiting two vulnerabilities, CVE-2026-60137 and CVE-2026-63030, to gain remote control of millions of WordPress websites. This widespread exploitation began shortly after the vulnerabilities were disclosed, targeting one of the internet's largest attack surfaces.
Indicators of Compromise
- cve — CVE-2026-63030
- cve — CVE-2026-60137
Entities
WordPress (product)