Trusted Design

Exploitation in the Wild of wp2shell

概要

A critical pre-authentication remote code execution vulnerability chain dubbed "wp2shell" affecting WordPress Core has been actively exploited in the wild. The vulnerability chain, consisting of CVE-2026-63030 and CVE-2026-60137, allows unauthenticated attackers to gain remote code execution on default WordPress installations. Multiple threat actors have been observed exploiting these vulnerabilities almost immediately after public disclosure, deploying persistent webshells and backdoors through malicious plugin uploads. Post-exploitation activities include user enumeration, local file inclusion attempts, and admin panel access. Three distinct PHP webshells have been identified, ranging from simple one-liners to sophisticated 150KB attack platforms disguised as legitimate WordPress plugins. Organizations should prioritize patching or implementing WAF mitigations to block access to WordPress Batch API endpoints.

Created: 2026-07-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

類似するPulseは見つかりませんでした。

このPulseに関連する脅威アクター (事実ベース)

事実ベースの脅威アクターは見つかりませんでした。

このPulseに関連する脅威アクター (推論ベース)

推論ベースの脅威アクターは見つかりませんでした。

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る