Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: WordPress website administrators
Incident: Mass exploitation of the wp2shell vulnerability chain for unauthenticated RCE.
Impact: Complete server compromise and potential deployment of remote access trojans.
Attacker: Unidentified threat actors
Analysis: Threat actors are chaining a route confusion bug in the REST API (CVE-2026-60137) with a secondary flaw (CVE-2026-63030) to achieve unauthenticated remote code execution. The ‘wp2shell’ campaign targets stock WordPress installations, enabling attackers to bypass authentication, exfiltrate credentials, and deploy malicious tools. Observed post-exploitation activity includes the installation of rogue plugins and the Overlord RAT.
Recommendations: Update WordPress to the latest patched version immediately.; Audit WordPress instances for unauthorized admin accounts and suspicious plugins.; Enable persistent object caching to block the primary RCE vector.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source