Threat Intelligence Brief
Curated summary with source attribution
Source: securityweek.com
Threat Risk: High
Victim: WordPress website administrators
Incident: Active exploitation of WP2Shell vulnerabilities CVE-2026-60137 and CVE-2026-63030.
Impact: Full site compromise via unauthenticated remote code execution.
Attacker: Unidentified threat actors
Analysis: The WP2Shell campaign chains a high-severity SQL injection (CVE-2026-60137) with a critical arbitrary code execution bug (CVE-2026-63030). Because these affect stock installations, the attack surface is massive and requires no prior authentication or plugin configuration. The speed of weaponization indicates a shrinking window between disclosure and exploitation, likely accelerated by AI-assisted tooling.
Recommendations: Immediately update WordPress to version 6.9.5 or 7.0.2.; Verify that auto-update mechanisms are enabled for core security patches.; Audit server logs for suspicious SQL injection patterns or unauthorized file modifications.
Source: SecurityWeek
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source