'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
Barely three days after disclosure, attackers are widely chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.
Record details
Published: 20 July 2026
Source: Dark Reading (AI security)
Category: News
Topics: Transparency
Retrieved: 21 July 2026
Related evidence
These records share source-supplied organisations, an exact publisher byline, automatic topics or regions. The reason is shown on every link; related does not mean supporting, agreeing with or verifying this record.
Weak Security Continues to Fuel Russian Cyberattacks
Dark Reading (AI security) · 13 July 2026
Thousands of Data Center Controllers Open to Takeover
Dark Reading (AI security) · 28 July 2026
Minnesota Water Utility Attacks Expose Sector's Cyber-Risks
Dark Reading (AI security) · 30 July 2026
AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
Dark Reading (AI security) · 5 August 2026
Fake Bug Report Hijacks AI Coding Agents at Scale
Dark Reading (AI security) · 30 June 2026
'Djinn' Stealer Targets Cloud, AI Credentials
Dark Reading (AI security) · 29 June 2026
How to cite this record
ethics.ai (20 July 2026), “'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover,” evidence record 12191, https://ethics.ai/record/12191 (originally published by Dark Reading (AI security)).
Use and limitations
This page is a stable index and citation surface for a source record. ethics.ai did not author the underlying report and has not independently verified every claim. Automatic topics may be imperfect. For consequential use, quote and cite the original publisher.