- Engineer — Act: Both CVEs are CISA KEV-listed with public PoCs and confirmed active exploitation deploying persistent webshells and rogue plugins. Patch WordPress Core immediately, then audit web root directories for unexpected PHP files and review installed plugins for unauthorized additions.
- SOC/IR — Act: Active webshell deployment creates a concrete detection surface — sweep web server access logs for unusual POST requests to new PHP files in WordPress directories since public PoC release, hunt for unexpected process spawning from web server processes, and add rules for plugin installation events outside change-window hours.
- Leader — Plan: WordPress is pervasive; CISA KEV listing on both CVEs signals confirmed active exploitation at scale. Confirm this week that engineering has inventoried all WordPress instances and is treating these as priority patches — a successful webshell compromise could trigger breach notification obligations if customer data is exposed.
- Signals: CVE-2026-60137 — CISA KEV: listed, EPSS 0.04, public PoC on GitHub, reported by 2 collected sources · CVE-2026-63030 — CISA KEV: listed, EPSS 0.09, public PoC on GitHub, reported by 3 collected sources