Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and ...
A researcher who discovered a critical vulnerability in WordPress has used OpenAI’s latest model to develop an exploit chain ...
Hackers are exploiting the "wp2shell" critical vulnerability suite (CVE-2026-63030 and CVE-2026-60137) affecting WordPress ...
Hackers are chaining together two newly discovered flaws to achieve remote code execution.
Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core ...
WordPress WP2Shell vulnerabilities expose millions of unpatched sites to full remote takeover - update to 7.0.2 now to stay ...
By chaining an SQL injection and an API vulnerability, attackers can inject code. WordPress has released an update, the ...
The wp2shell exploit allows attackers to gain full control of WordPress without any login. WordPress has issued emergency updates to patch actively exploited, critical vulnerabilities. The exploit ...
Just hours after fixes came out, attackers have begun exploiting two bugs that, when chained together, allow ...
Attackers have begun widely exploiting two critical vulnerabilities in WordPress that, when chained, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.
In-the-wild exploitation seen for the new WP2Shell WordPress vulnerabilities, officially tracked as CVE-2026-60137 and ...
Two patched WordPress vulnerabilities, chained as wp2shell, are under mass attack. AI helped find the flaw and weaponise it. Millions of sites may be exposed.