Critical WordPress 'wp2shell' Flaws Actively Exploited for Webshell Deployment
Attackers are actively exploiting two critical unauthenticated remote code execution vulnerabilities (CVE-2026-63030 and CVE-2026-60137) in WordPress Core by abusing the REST API's batch-processing feature to deploy webshells and malicious plugins. The core failure is delayed or absent patch application on internet-facing WordPress installations, leaving sites exposed even after fixes are available. This matters because webshells provide persistent, covert backdoor access that can lead to credential theft, data exfiltration, and full site compromise. The supply of malicious plugins further expands the attack surface, demonstrating how unpatched CMS platforms become launchpads for broader infrastructure attacks.
Tactical Insight
Immediate Actions
- Apply the latest WordPress Core patches immediately across all managed installations, prioritizing internet-facing sites.
- Audit all installed plugins and themes, removing any unrecognized or unauthorized additions that may have been injected by attackers.
- Scan web servers for webshell indicators using tools such as ClamAV, LMD, or a dedicated EDR solution.
Long-Term Improvements
- Enable automated patching or managed update pipelines for WordPress Core, plugins, and themes to minimize the window of exposure.
- Restrict the WordPress REST API to authenticated users only where anonymous access is not a business requirement.
- Maintain a vetted, version-controlled inventory of all approved plugins and themes to detect unauthorized additions quickly.
Detection Measures
- Deploy a Web Application Firewall (WAF) with rules targeting REST API abuse and known wp2shell exploit signatures.
- Implement file integrity monitoring on the WordPress web root to alert on unauthorized file creation or modification.
- Centralize and actively monitor web server and application logs for anomalous REST API calls, mass scanning activity, and privilege escalation attempts.