wp2shell is a name used for an unauthenticated WordPress Core exploitation chain that combines CVE-2026-63030 and CVE-2026-60137 to achieve remote code execution on exposed sites. The chain abuses route confusion in the WordPress REST API batch endpoint to bypass normal parameter sanitization and reach a SQL injection condition, enabling attackers to manipulate application state, enumerate users, create or assume administrative context, and ultimately execute arbitrary code on the server. It affects WordPress Core directly rather than relying on a vulnerable plugin or theme, making public-facing default installations a viable target when unpatched.
Observed exploitation has been active in the wild and has included opportunistic scanning as well as follow-on compromise activity. Reported post-exploitation behaviors include administrator-user enumeration, creation of new privileged accounts, malicious plugin upload for persistent access, and deployment of PHP webshells. Some observed webshells used stealth features such as deceptive error responses and self-cleaning behavior to reduce visibility after command execution. The exploitation chain has also been associated with attempts to access sensitive local files after initial compromise.
The activity has been described by multiple defenders and researchers as a critical pre-authentication WordPress Core RCE issue with broad internet exposure. Affected versions include the full chain on WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1, while CVE-2026-60137 alone also affected 6.8.0 through 6.8.5. Fixed releases were issued in WordPress 6.8.6, 6.9.5, and 7.0.2. Because wp2shell is fundamentally an exploit chain that commonly results in webshell or malicious plugin deployment, it is best characterized operationally as a webshell-associated intrusion mechanism targeting WordPress on Linux-hosted web servers.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
Add WordPress wp2shell exposure scanner (CVE-2026-63030 + CVE-2026-60137) ... Includes Cloudflare WAF bypass and self-cleaning webshell with stealth mode.
Add WordPress wp2shell exposure scanner (CVE-2026-63030 + CVE-2026-60137) ... Includes Cloudflare WAF bypass and self-cleaning webshell with stealth mode.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
Post-authentification : utilisation des credentials récupérés (après crackage offline du hash) pour s’authentifier
With ordinary stock file-modification permissions, that account can upload a plugin containing a directly requestable PHP endpoint.
The command-execution alerts show /usr/sbin/apache2 as the parent and /usr/bin/dash running sh -c -- id, whoami, and hostname.
26 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Related : WP2Shell WordPress Vulnerabilities Exploited in the Wild
A named exploit/webshell tool used to chain WordPress REST API batch route confusion with blind SQL injection to achieve unauthenticated remote code execution on vulnerable WordPress versions, create an administrator account, deploy a webshell, execute payloads, and then remove the webshell for stealth.
A named exploit chain that combines CVE-2026-60137 and CVE-2026-63030 to achieve pre-authentication remote code execution against WordPress Core, enabling attacker footholds such as admin account creation and subsequent code execution.
Named attack/exploit chain for WordPress that begins with an unauthenticated SQL injection via the REST Batch API and is escalated to administrative access and arbitrary code execution by installing a malicious plug-in.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.