Skip to main content
CyberConfirmedHighDevelopingFeatured
10.0

Active exploitation of critical WordPress wp2shell vulnerabilities detected

Threat actors are actively exploiting two critical vulnerabilities, CVE-2026-63030 and CVE-2026-60137, in WordPress Core to deploy persistent webshells and malicious plugins. The scope of the compromise and the specific threat actor attribution remain uncertain, posing a significant risk to server integrity across the WordPress ecosystem.

BleepingComputerabout 5 hours agoCredibility 54%View source

Score Breakdown

Mosaic Score10.0
Confidence0.9
Significance0.8
Source credibility0.5
Source

Part of 2 situations

Related signals

8 found