Two critical security flaws identified as CVE-2026-63030 and CVE-2026-60137 in the wp2shell plugin are being actively exploited to install malicious webshells on WordPress sites. This exploitation allows attackers to take over affected websites, posing significant risks to website administrators and their users. The vulnerabilities are particularly concerning due to their widespread potential impact, as WordPress powers a substantial portion of the internet. Organizations using this plugin are urged to assess their systems immediately to prevent unauthorized access and potential data breaches.
The exploitation of these vulnerabilities involves attackers inserting webshells into the compromised WordPress sites, which then enable them to execute arbitrary commands on the server. This kind of access can lead to a complete site takeover, allowing attackers to modify site content, steal sensitive data, or even use the site as a launching pad for further attacks. The implications are severe, making it crucial for affected parties to respond swiftly.
To mitigate the risks associated with these vulnerabilities, website owners and administrators should ensure that their WordPress installations and plugins are up to date with the latest security patches. Additionally, conducting regular security audits and employing robust security measures such as intrusion detection systems can help in identifying and neutralizing such threats before they cause significant harm.


