Multiple outlets report that newly disclosed “WP2Shell” vulnerabilities are being exploited against WordPress sites shortly after public disclosure. SANS Internet Stormcast says the issue was first shared without a CVE identifier and later assigned CVE-2026-63030. It describes the problem as a SQL injection in WordPress Core that can enable unauthenticated remote code execution, and notes that exploitation begins soon after the vulnerability details are released.
SecurityWeek similarly reports that exploitation starts in the wild soon after disclosure and references both CVE-2026-60137 and CVE-2026-63030 as the relevant vulnerabilities being targeted. Dark Reading adds that attackers are chaining the two CVEs together and launching exploit attempts at scale, referring to WordPress as one of the largest attack surfaces on the internet. Overall, the reporting converges on rapid, widespread attacker activity and on the use of the two CVEs in combination to compromise WordPress installations.