HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

WP2Shell Chains CVE‑2026‑60137 & CVE‑2026‑63030 for Remote Takeover of Millions of WordPress Sites

Attackers are weaponizing two newly disclosed WordPress core vulnerabilities (CVE‑2026‑60137, CVE‑2026‑63030) to gain unauthenticated remote control of unpatched sites. The rapid exploitation highlights the need for continuous vulnerability management and auditable patch evidence under SOC 2.

LiveThreat™ Intelligence · 📅 July 21, 2026· 📰 darkreading.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
darkreading.com

WP2Shell Exploits CVE‑2026‑60137 & CVE‑2026‑63030 to Enable Remote Takeover of Millions of WordPress Sites

What It Is — A weaponized exploit chain, dubbed “WP2Shell,” combines two newly disclosed WordPress core vulnerabilities (CVE‑2026‑60137 and CVE‑2026‑63030) to achieve unauthenticated remote code execution.

Exploitability — Public PoCs appeared within 48 hours of disclosure; threat actors are already scanning and weaponizing the chain at scale. CVSS v3.1 scores are 9.8 (critical) for CVE‑2026‑60137 and 9.3 (critical) for CVE‑2026‑63030.

Affected Products — WordPress 5.9‑6.4 (core) on any hosting environment that has not applied the emergency patches released by the WordPress security team.

Why It Matters for Compliance & Audit Readiness

  • Continuous Vulnerability Management – SOC 2 CC6.1 (Vulnerability Management) requires documented, timely remediation; the rapid weaponization of WP2Shell underscores the need for automated patch‑tracking evidence.
  • Defensible Audit Trail – Demonstrating that you regularly ingest vendor advisories (e.g., WordPress security releases) and retain remediation proof satisfies auditors and reduces “unknown‑risk” findings.
  • Enterprise Buyer Expectations – Large customers now demand proof that web‑application stacks are continuously monitored for critical CVEs before signing contracts.

Recommended Actions

  • Apply the WordPress emergency patches for CVE‑2026‑60137 and CVE‑2026‑63030 immediately.
  • Verify that all managed WordPress instances are running a patched version via an automated inventory scan.
  • Map the remediation to SOC 2 CC6.1 controls and capture patch‑application logs as immutable audit evidence.
  • Enable continuous external scanning for WP2Shell activity (e.g., web‑shell signatures, anomalous outbound traffic).
  • Review third‑party plugins/themes for additional exposure; enforce a “no‑unvetted code” policy.

Source: Dark Reading – WP2Shell Opens Millions of WordPress Sites to Remote Takeover

📰 Original Source
https://www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeover

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →