A #Wordpress site belonging to an friend (I’m not the admin...) was successfully hacked using #wp2shell (17.07.2026; #CVE-2026-63030), just 5 days after the first exploit published (20.07.). Another 5 days later, the website was abused for SEO spamming and for hosting phishing…
If you haven't already, update your Wordpress (preferably yesterday…) and also enable automatic updates for themes and plug-ins!
I found several PHP backdoors/webshells (see @abuse_ch@ioc.exchange Malware Bazaar and #VirusTotal (hashes below)). Interestingly, not every sample was detected by the #YARA rules from @cyb3rops@infosec.exchange and https://github.com/ruppde/yara_rules
tl;dr #wp2shell is being actively exploited, patch immediately and enable automatic updates.
Hashes:
1093b4045b45a8498d146e31788c25769f992056c8ffc582b5d8c06598598966
05e3884a478d3bc8fd7285dabb74107422f1615d2d7f80df9b8438d4beb663da
bb9136494a546368e7c9b6252c2e1c5af9327c07947908a9ba6fdd78fb4bf4cf
1e7ca9074cc2eca8d366022629f665d9ffaa79e0621bb579bf5aabe681cb07e8
8ebaf3ba0be7b62269aaf333cfaf66c1dea6e8ee495a917691beb550b4bbf0ab
e3fb920aa70c7ad5c67b4d9b8e60954f5e0c1a07c0eba09505816b966f4d1a3c
165e94c87ef17389c8de25ba2a6c31b348e3c916dab89d0dd3708156414f3de5
b55cf5af8b57e9d56c69d00e023e2384c7eb184614c2a2a283062ebeaf4a26c6
a46230a1638b9b341d15a640ead1b885548c1d1e5a149657e8e315540a068be8
7918f29993383e579ef33bd0d8e766fd2ce047dce83bac51efb5fe17578b6cdf
ae9ee9db7c41e04c531298782b908766c769a899aa92df3f64f4a83baa77ad09
About This Hashtag
#wp2shell
13 posts
Last used Aug 10
#wp2shell
13 posts· Last used Aug 10
#WordPressCore "#wp2shell" RCE flaws get public exploits, patch now
https://www.bleepingcomputer.com/news/security/wordpress-core-wp2shell-rce-flaws-get-public-exploits-patch-now/
#cybersecurity #WordPress
wp2shell, a WordPress Core RCE chain (CVE-2026-63030, CVE-2026-60137), is exploited in the wild. Public PoC code is out. Patch WordPress now.
#wp2shell #WordPress #RCE #CVE202663030 #CVE202660137 #InfoSec #WebSecurity #PatchNow
https://securityonline.info/wp2shell-wordpress-core-rce/?utm_source=mastodon&utm_medium=jetpack_social
So, more explanation of wp2shell recently just popped out.
The vulnerability were found by GPT 5.6 Sol. By using modified prompt from how it found the solution of Cycle Double Cover conjecture.
It was initially found a SQL Injection, but after asked again if it can be elevated to RCE, it confirms it in 4 hours.
Technical explanation on the vulnearbility also can be found in this writeup, have a good read fellas.
https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/
#cybersecurity #infosec #security #wordpress #chatgpt #gptsol #wp2shell #airesearch #llm #vulnerability #vulnerabilityresearch
The wp2shell chain turns two WordPress core bugs into unauthenticated RCE on default installs. Update to 6.9.5, 7.0.2, or 6.8.6 immediately.
#WordPress #wp2shell #RCE #SQLInjection #RESTAPI #CVE
https://securityexpress.info/wp2shell-wordpress-rce/?utm_source=mastodon&utm_medium=jetpack_social
Replying to @wdormann@infosec.exchange
@wdormann@infosec.exchange
Just had a quick squiz at some servers I run with WordPress on based on the URLs mentioned in the article
egrep -ir "rest_route=/batch/v1|wp/v2/categories|wp/v2/users" /var/log/apache2/*
21 requests starting 18/07/2026 05:30 UTC
None of the requests have anything in common.
Seems mostly like people poking around rather than spraying at this stage.
#WordPress #CVE-2026-63030 #CVE-2026-60137
#wp2shell
🚨 CRITICAL: WordPress Core "wp2shell" RCE
A single anonymous HTTP request can lead to Remote Code Execution on vulnerable WordPress Core installations.
⚠️ No plugins.
⚠️ No themes.
⚠️ No authentication required.
Tracked as:
🔴 CVE-2026-63030 (REST API Batch Route Confusion → RCE)
🔴 CVE-2026-60137 (Facilitated SQL Injection)
Affected versions
• WordPress 6.9.0–6.9.4
• WordPress 7.0.0–7.0.1
✅ Update immediately to WordPress 6.9.5 or 7.0.2. Due to the severity, WordPress has enabled forced automatic security updates for affected installations.
🔗 Full technical analysis:
https://thecybersecguru.com/news/wordpress-core-rce-wp2shell/
#WordPress #WordPressSecurity #wp2shell #CVE202663030 #CVE202660137 #RCE #RemoteCodeExecution #SQLInjection #RESTAPI #CyberSecurity #InfoSec #WebSecurity #WebsiteSecurity #PatchNow #ThreatIntelligence #BlueTeam #SOC #Linux #PHP #ZeroDay #SecurityResearch #SysAdmin #DevSecOps
A critical WordPress wp2shell vulnerability allows remote code execution without a login. Learn how to scan your site and apply the urgent 7.0.2 update.
#WordPress #wp2shell #CyberSecurity #Malware
https://meterpreter.org/wordpress-wp2shell-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
Cloudflare deploys emergency WAF rules to block the critical WordPress wp2shell vulnerability. Update your site now to prevent severe RCE security risks.
#WordPress #Cloudflare #wp2shell #CyberSecurity #WAF
https://securityonline.info/wordpress-wp2shell-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
⚡ UPDATE: #wp2shell now has two CVEs, and a working proof-of-concept is public.
CVE-2026-63030 breaks REST batch routing CVE-2026-60137 injects SQL
Chained, they give an anonymous attacker code execution on affected WordPress sites.
How the exploit path works: https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
#Wordpress: Critical Remote Code Execution (#RCE) chain of vulnerabilities CVE-2026-63030 and #SQLi SQL Injection CVE-2026-60137 dubbed #wp2shell in WordPress Core threaten 500+ million of websites.
Patch now!:
👇
https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
Heyoo, there's a #wp2shell WordPress core RCE situation going on. The @vulncheck@infosec.exchange research team sussed out what we could determine from patches and public info, and so far, while it ain't *good*, it could maaaybe be worse. I guess we'll see come Sunday/Monday what details and exploitation status looks like, but it feels like we're gonna see attacks start basically now.
https://www.vulncheck.com/blog/wp2shell
WordPress pre-auth RCE CVE-2026-63030 chains a REST batch bug with SQL injection. Details and a public PoC are out. Update to WordPress 7.0.2 now.
#WordPress #PreAuthRCE #CVE202663030 #SQLInjection #wp2shell #WebSecurity #InfoSec
https://securityonline.info/wordpress-pre-auth-rce-cve-2026-63030/?utm_source=mastodon&utm_medium=jetpack_social
You've seen all posts