CuraSec

Act archived

WordPress wp2shell RCE Chain Exploited in Mass Scanning Campaign

2026-07-21 12:43 UTC · The Hacker News · read the source ↗ #wordpress#rce#active-exploitation
  • Engineer — Act: Both CVEs have public PoCs and exploitation is already underway with mass scanning — patch all WordPress instances to the fixed versions immediately and audit exposed sites for webshell artifacts, especially any unexpected PHP files or modified themes.
  • SOC/IR — Act: Active exploitation confirmed since early Saturday UTC; hunt for webshell uploads and anomalous POST requests targeting WordPress endpoints across your estate, and sweep for post-compromise persistence on any internet-facing WordPress hosts.
  • Leader — Plan: Active exploitation with mass scanning is in progress but hasn’t reached Log4Shell-scale board attention yet; confirm whether WordPress appears in your web portfolio and ensure it’s on your engineering team’s immediate patching queue this week.
  • Signals: CVE-2026-60137 — CISA KEV: not listed, EPSS 0.04, public PoC on GitHub · CVE-2026-63030 — CISA KEV: not listed, EPSS 0.09, public PoC on GitHub, reported by 2 collected sources
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.