Critical wp2shell WordPress flaws exploited to install webshells
Hackers are exploiting the wp2shell critical vulnerability suite affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers.
Intelligence analysis by Llama

The critical exploit chain abuses the WordPress REST API's batch-processing feature, allowing remote attackers to execute code on vulnerable installations without authentication. WordPress has patched the issue in versions 7.0.2, 6.9.5, and 6.8.6.
Imagine someone found a way to hack into WordPress sites without needing a password. They can install bad plugins and take control of the site. This is what's happening with the wp2shell vulnerability. It's like a backdoor that lets hackers in. WordPress has fixed the problem, but site owners need to update their sites to stay safe.
Analysis
A Critical Vulnerability Suite Exploited
The wp2shell vulnerability suite, consisting of CVE-2026-63030 and CVE-2026-60137, has been exploited by hackers to deploy persistent webshells and install malicious plugins on affected WordPress sites. The critical exploit chain takes advantage of the WordPress REST API's batch-processing feature, allowing remote attackers to execute code on vulnerable installations without the need for authentication.
The Exploit Chain
The exploit chain involves several stages, including mass-scanning for vulnerable WordPress installations, abuse of WordPress plugin upload functionality, installation of PHP webshells, querying the WordPress REST API to collect administrator usernames and email addresses, and local file inclusion attempts targeting wp-config through admin-ajax.php to retrieve database credentials and authentication keys.
The Impact
The exploitation of the wp2shell vulnerability has significant implications for WordPress site owners and administrators. The installation of malicious plugins and webshells can lead to unauthorized access, data breaches, and other security risks. It is essential for site owners to update to the patched versions of WordPress, review logs for wp2shell-related requests, inspect installed plugins, and check for rogue PHP file additions or newly created admin accounts.
The Response
WordPress has patched the issue in versions 7.0.2, 6.9.5, and 6.8.6. Cloud security company Wiz has shared technical details about observed attacks leveraging wp2shell, and a dashboard has been created to help track the patch rate live. The portal reports an 81.6% patch rate out of a sample of 124,580 websites evaluated.
Key points
- Hackers are exploiting the wp2shell critical vulnerability suite affecting WordPress Core to deploy persistent webshells and install malicious plugins on affected servers.
- The critical exploit chain abuses the WordPress REST API's batch-processing feature, allowing remote attackers to execute code on vulnerable installations without authentication.
- WordPress has patched the issue in versions 7.0.2, 6.9.5, and 6.8.6.
- Site owners need to update to the patched versions of WordPress and review their logs for wp2shell-related requests to prevent the installation of malicious plugins and webshells.
If site owners update to the patched versions of WordPress and review their logs for wp2shell-related requests, they can prevent the installation of malicious plugins and webshells. This will help to prevent unauthorized access and data breaches.
If site owners do not update to the patched versions of WordPress, they risk installing malicious plugins and webshells, which can lead to unauthorized access, data breaches, and other security risks.



