Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
3 results for “CVE-2026-60137”
Critical wp2shell WordPress flaws exploited to install webshells
Two critical zero-day vulnerabilities in WordPress Core—CVE-2026-63030 and CVE-2026-60137, collectively dubbed 'wp2shell'—are actively exploited to install persistent webshells and malicious plugins on unpatched servers.
Jul 21, 2026
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers are actively exploiting two critical WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137), collectively named wp2shell, enabling unauthenticated remote code execution and full site compromise.
Jul 21, 2026
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
A newly disclosed vulnerability chain (CVE-2026-60137 and CVE-2026-63030) is already being actively exploited to remotely compromise WordPress sites at scale, representing an urgent, real-world cybersecurity incident.
Jul 21, 2026