Back to all lessons
Awareness Lessons
3 months ago

WordPress wp2shell RCE Exploited at Scale via Public Exploit Code

Two chained critical vulnerabilities in default WordPress installations (CVE-2026-63030 and CVE-2026-60137) enabled unauthenticated remote code execution, leading to full site compromise including credential theft and malicious plugin deployment. The root cause is a failure to apply patches promptly after public disclosure, compounded by the fact that default WordPress configurations were vulnerable with no additional hardening required by attackers. The public release of working exploit code dramatically shortened the window between disclosure and mass exploitation, underscoring that the patch cycle must be treated as a race against adversaries. This matters because WordPress powers a significant portion of the web, meaning delayed patching exposes millions of sites simultaneously to automated, low-effort attacks.

Tactical Insight

Immediate actions

  • Apply the latest WordPress core patches immediately, prioritizing any internet-facing installations running the affected default configuration.
  • Run an authenticated vulnerability scan across all WordPress assets to identify unpatched instances before attackers do.
  • Audit installed plugins and remove or disable any unauthorized or recently installed plugins that may indicate post-exploitation activity.

Long-term improvements

  • Implement an emergency patching SLA (e.g., 24–48 hours) for critical RCE vulnerabilities affecting internet-facing web platforms.
  • Harden default WordPress configurations by disabling file editing, restricting plugin installation, and enforcing least-privilege database accounts.
  • Maintain a complete, up-to-date inventory of all web properties and their CMS versions to enable rapid response when new CVEs are published.

Detection measures

  • Deploy a Web Application Firewall (WAF) with rules targeting the wp2shell exploit chain to block or alert on active scanning and exploitation attempts.
  • Enable centralized logging of all WordPress admin actions, authentication events, and plugin changes and alert on anomalous activity.
  • Subscribe to threat intelligence feeds and WordPress security advisories to receive early warning of newly disclosed vulnerabilities and active exploit campaigns.