WP2Shell WordPress Vulnerabilities Exploited in the Wild, Forced Updates Enabled

AI-generated NewsSnap summary based on source reporting.
Published: 2026-07-20T05:21:00Z
Category: technology
Source: SecurityWeek

Two newly patched WordPress vulnerabilities, tracked as CVE-2026-60137 and CVE-2026-63030 (dubbed WP2Shell), are being actively exploited in the wild. The flaws can be exploited by an anonymous user in a stock WordPress installation without plugins. WordPress has released patches in versions 6.9.5 and 7.0.2 and enabled forced updates due to the severity.

Want more?

Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.

Open NewsSnap.ai