Threat actors have released public exploit code for the WordPress core remote code execution vulnerabilities, named wp2shell. Tracked as CVE-2026-63030 and CVE-2026-60137, the vulnerabilities can be chained together to achieve pre-authentication remote code execution. Adam Kues of Searchlight Cyber discovered and reported the vulnerability to WordPress. The article mentioned that more than 500 million websites use WordPress, which … Continue reading “WordPress wp2shell Vulnerabilities Exploited in the Wild (CVE-2026-63030 & CVE-2026-60137)”