WP2Shell Exploits CVE‑2026‑60137 & CVE‑2026‑63030 to Enable Remote Takeover of Millions of WordPress Sites
What It Is — A weaponized exploit chain, dubbed “WP2Shell,” combines two newly disclosed WordPress core vulnerabilities (CVE‑2026‑60137 and CVE‑2026‑63030) to achieve unauthenticated remote code execution.
Exploitability — Public PoCs appeared within 48 hours of disclosure; threat actors are already scanning and weaponizing the chain at scale. CVSS v3.1 scores are 9.8 (critical) for CVE‑2026‑60137 and 9.3 (critical) for CVE‑2026‑63030.
Affected Products — WordPress 5.9‑6.4 (core) on any hosting environment that has not applied the emergency patches released by the WordPress security team.
Why It Matters for Compliance & Audit Readiness
- Continuous Vulnerability Management – SOC 2 CC6.1 (Vulnerability Management) requires documented, timely remediation; the rapid weaponization of WP2Shell underscores the need for automated patch‑tracking evidence.
- Defensible Audit Trail – Demonstrating that you regularly ingest vendor advisories (e.g., WordPress security releases) and retain remediation proof satisfies auditors and reduces “unknown‑risk” findings.
- Enterprise Buyer Expectations – Large customers now demand proof that web‑application stacks are continuously monitored for critical CVEs before signing contracts.
Recommended Actions
- Apply the WordPress emergency patches for CVE‑2026‑60137 and CVE‑2026‑63030 immediately.
- Verify that all managed WordPress instances are running a patched version via an automated inventory scan.
- Map the remediation to SOC 2 CC6.1 controls and capture patch‑application logs as immutable audit evidence.
- Enable continuous external scanning for WP2Shell activity (e.g., web‑shell signatures, anomalous outbound traffic).
- Review third‑party plugins/themes for additional exposure; enforce a “no‑unvetted code” policy.
Source: Dark Reading – WP2Shell Opens Millions of WordPress Sites to Remote Takeover