Wp2shell is a vulnerability tracked across 5 threat clusters and 25 intelligence report mentions on ThreatCluster. First observed July 17, 2026; most recent activity July 21, 2026.
On July 17, 2026, WordPress disclosed two critical vulnerabilities, CVE-2026-63030 and CVE-2026-60137, affecting its core software. CVE-2026-63030 is a remote code execution (RCE) vulnerability in the REST API, while…
A critical vulnerability chain, dubbed wp2shell, has been identified in WordPress Core, allowing unauthenticated attackers to execute arbitrary code on default installations. This vulnerability is tracked as…
Cybersecurity firms report that hackers are actively exploiting two critical vulnerabilities in WordPress versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. WordPress recently patched these flaws, urging immediate updates.…
Researchers at Searchlight Cyber utilized GPT-5.6 Sol Ultra to identify a critical pre-authentication remote code execution (RCE) vulnerability in WordPress. The AI model reportedly found the vulnerability after…
BeyondTrust has issued a warning regarding a critical remote code execution (RCE) vulnerability in its Remote Support and Privileged Remote Access software. The flaw, tracked as CVE-2026-1731, allows unauthenticated…