[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:critical-wp2shell-wordpress-flaws-exploited-to-install-webshells-mrx3yda3":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":14,"action_required":20,"article_ids":21,"ioc_summary":23,"source_urls":24,"status":26,"expires_at":27,"created_at":28,"updated_at":29,"articles":30},"11d0f960-e3a2-4e91-be91-f4fc6b9ad301","Critical wp2shell WordPress flaws exploited to install webshells","critical-wp2shell-wordpress-flaws-exploited-to-install-webshells-mrx3yda3","Critical unauthenticated RCE vulnerabilities in WordPress Core (CVE-2026-63030, CVE-2026-60137) are being actively exploited via REST API batch processing to deploy webshells and malicious plugins. All unpatched WordPress instances are at risk. Attackers are actively scanning and compromising sites to establish persistence and steal credentials.","critical","advisory",[12,13],"CVE-2026-63030","CVE-2026-60137",[15,16,17,18,19],"WordPress Core","SearchLight Cyber","Wiz","Sans Technology Institute","Defiant","Immediately identify all WordPress instances in your environment and verify they are patched to the latest version. Scan web logs for REST API batch requests (\u002Fwp-json\u002Fbatch) and monitor for suspicious plugin installations or webshell uploads in wp-content directories.",[22],"36de568d-1ed1-460f-9525-107d953d1e7f",null,[25],"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcritical-wp2shell-wordpress-flaws-exploited-to-install-webshells\u002F","active","2026-07-25T06:05:56.409+00:00","2026-07-23T06:05:59.613227+00:00","2026-07-23T06:09:42.677226+00:00",[31],{"id":22,"title":6,"url":25}]