WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites.
Intelligence analysis by Llama

A public exploit has been released for two critical WordPress vulnerabilities, allowing attackers to gain remote code execution and compromise vulnerable websites. The exploit chain, discovered by Searchlight Cyber, essentially allows unauthenticated attackers to gain remote code execution on default WordPress installations in any WordPress version released since December 2025.
Imagine you have a website on WordPress, and someone finds a way to hack into it without needing a password. They can then do whatever they want with your website, like stealing your information or putting up fake stuff. This is what's happening with the WordPress wp2shell exploit.
Analysis
A $60B Vote of Confidence
The exploitation of the two critical WordPress vulnerabilities has the potential to compromise a large number of websites, making it a significant security concern for WordPress users. The vulnerabilities, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. By the early hours of Saturday morning (UTC), successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public.
Why Cursor?
The exploit chain, discovered by Searchlight Cyber using OpenAI GPT 5.6 Sol in over 10 hours, essentially allows unauthenticated attackers to gain remote code execution on default WordPress installations in any WordPress version released since December 2025. The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins.
The Road Ahead
Defenders are recommended to inspect their WordPress instances for new administrator accounts, malicious plugins, or other suspicious files, regardless of whether they've been patched, to completely root out the threat. The potential blast radius was reduced due to defensive measures already in place, such as WordPress's automatic background updates for security releases and some infrastructure providers receiving advance notice and deploying virtual patches quickly.
Key points
- Two critical WordPress vulnerabilities have been exploited, allowing attackers to gain remote code execution and compromise vulnerable websites.
- The vulnerabilities, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell.
- The exploit chain, discovered by Searchlight Cyber, essentially allows unauthenticated attackers to gain remote code execution on default WordPress installations in any WordPress version released since December 2025.
- Defenders are recommended to inspect their WordPress instances for new administrator accounts, malicious plugins, or other suspicious files, regardless of whether they've been patched, to completely root out the threat.
If the WordPress community comes together to quickly patch the vulnerabilities and provide guidance on how to secure websites, the impact of the exploit can be minimized. Additionally, the release of a public exploit may lead to a greater awareness of the importance of security in the WordPress ecosystem, leading to improved security measures in the future.
The exploitation of the vulnerabilities could lead to a large number of websites being compromised, resulting in significant financial losses and damage to reputation. Additionally, the release of a public exploit may lead to a surge in malicious activity, making it difficult for defenders to keep up.



