11 views 58 secs 0 comments

‘WP2Shell’ Opens Millions of WordPress Sites to Remote Takeover

In Vulnerabilities, News
July 21, 2026

If you haven’t patched already, get busy. DarkReading reports:

Attackers have begun widely exploiting two critical vulnerabilities in WordPress that, when chained, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.

The attacks are being fueled by the ready availability of numerous proof-of-concept exploits for the two bugs, identified as CVE-2026-60137 and CVE-2026-63030. Researchers at Searchlight Cyber discovered the flaws using GPT-5.6 Sol Ultra during vulnerability research and have dubbed the exploit chain “WP2Shell.”

The flaws affect tens — and potentially even hundreds – of millions of WordPress sites using default install configurations worldwide, giving attackers a vast pool of targets to try and exploit. 

Read more at DarkReading.