Attackers have begun to exploit two critical vulnerabilities
in WordPress that, when combined together, enable unauthenticated
remote code execution (RCE) and complete compromise of vulnerable
websites. The two security flaws, tracked as CVE-2026-63030 and
CVE-2026-60137, have been codenamed wp2shell. "By the early hours
of Saturday morning (UTC), successful exploitation was already
well
Read more https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html

