The release of functional exploit code for the WordPress core wp2shell flaw has triggered a wave of mass scanning and takeover attempts against unpatched websites, according to researchers tracking the activity.
The bug, registered as CVE-2026-60137, enables unauthenticated attackers to run arbitrary code on affected WordPress installations. A second related issue, CVE-2026-63030, broadens the attack surface further. Both Security Affairs and The Register reported a dramatic uptick in scanning traffic after the exploit entered the public domain.
The attack pattern follows a well-worn playbook: automated scanners hunt for vulnerable installations, plant webshells or backdoor admin accounts, and use the compromised site as a launching pad for further attacks. Given how widely WordPress is deployed globally, the pool of potential targets is enormous.
Security teams running WordPress should apply the latest core patches immediately. Any site still on an unpatched version should be treated as potentially compromised. Defenders can look for unusual admin accounts, unexpected file changes, and outbound connections from the web server to unfamiliar IP addresses as possible indicators of a successful attack.

