Back to all news
Security

'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

Dark Reading·July 20, 2026·1 min read
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover

Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to launch exploit attempts against millions of WordPress sites. The 'WP2Shell' vulnerability opens one of the largest attack surfaces on the Internet to remote takeover. Security teams are urged to patch immediately as active exploitation escalates.

Read at Dark Reading
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store