WP2Shell WordPress Vulnerabilities Exploited in the Wild, Forced Updates Enabled
Two newly patched WordPress vulnerabilities, tracked as CVE-2026-60137 and CVE-2026-63030 (dubbed WP2Shell), are being actively exploited in the wild. The flaws can be exploited by an anonymous user in a stock WordPress installation without plugins. WordPress has released patches in versions 6.9.5 and 7.0.2 and enabled forced updates due to the severity.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.