Cookie Consent by Free Privacy Policy Generator

WordPress WP2Shell Vulnerabilities Exploited in the Wild

Exploitation of newly disclosed WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030, collectively referred to as WP2Shell, began shortly after public disclosure. The vulnerabilities affect WordPress installations and allow attackers to gain unauthorised access or execute malicious code. WordPress remains one of the most widely used content management systems globally, powering a significant proportion of websites across all sectors including UK businesses, public sector organisations, charities and SMEs. The rapid exploitation following disclosure reflects a consistent pattern where attackers monitor vulnerability announcements and move quickly to scan for and exploit unpatched systems before organisations have had time to apply updates. This creates a narrow window of opportunity for defenders to patch systems before they are targeted, particularly for internet-facing websites that are easily discoverable through automated scanning.

Why this matters for UK organisations

For UK organisations running WordPress sites, whether for public-facing websites, intranets, blogs or e-commerce platforms, this incident is a reminder of the operational risk that comes with any widely deployed software platform. The speed at which exploitation began underscores the importance of having a clear and rapid patch management process, particularly for internet-facing systems. WordPress sites are often managed by marketing teams, communications teams or external agencies rather than central IT, which can create gaps in visibility, ownership and timely patching. The risk is not limited to defacement or disruption; compromised WordPress sites can be used to host malicious content, distribute malware, steal credentials or serve as an entry point into broader network environments. In some cases, attackers have used compromised websites to pivot into internal systems, particularly where websites share infrastructure or credentials with other services. The challenge for many organisations is that they may not have a complete inventory of all WordPress installations across the business, including shadow IT sites, test environments or sites managed by third parties.

What to review

UK businesses should review how WordPress installations are managed, who is responsible for applying updates, and whether there is a complete inventory of all WordPress sites across the organisation including those managed by third parties or external agencies. Consider whether your patching process can respond within hours or days of a critical vulnerability disclosure, and whether there are compensating controls such as web application firewalls, intrusion detection systems or monitoring in place for sites that cannot be patched immediately. Review whether WordPress sites are segmented from internal networks and whether there are controls to limit the impact of a compromised website. Consider whether there is a process for regularly reviewing plugins, themes and other WordPress components for known vulnerabilities, and whether there is clear ownership for maintaining the security of WordPress environments across IT, communications, marketing and external suppliers. Ensure there is a plan for responding to a compromised website, including how to restore from clean backups, how to identify the scope of the compromise, and how to communicate with stakeholders if the site is taken offline for remediation.

Source: SecurityWeek

News and blog posts
Today's brief focuses on three areas where trust in established security...
TechCrunch and Dark Reading report that two critical vulnerabilities in...
SecurityWeek reports that two zero-day vulnerabilities in SonicWall firewall...
Help Net Security reports that independent research by Milan Brož and...