THREAT OPS › Threat News › WP2Shell WordPress Exploit Technical Analysis and Real Attack Data
WP2Shell WordPress Exploit Technical Analysis and Real Attack Data
<p>On July 17th, 2026, the WordPress Security Team released updates to WordPress core addressing a critical vulnerability chain that can be leveraged by unauthenticated attackers to create an administrator account and then execute code through normal administrator capabilities, such as uploading a plugin.</p> <p>The chain consists of two vulnerabilities: an unauthenticated SQL injection vulnerabil
MITRE ATT&CK techniques
Indicators of compromise
- 8ec93bb7e5ec96ab4636699e413382c9md5
- 4418c9327e7455cc20ecc3238895e0d9md5
- 00000000000000000000000000000000md5
- CVE-2026-60137cve
- CVE-2026-63030cve
- https://www.cve.org/CVERecord?id=CVE-2026-60137url
- https://www.cve.org/CVERecord?id=CVE-2026-63030url
- https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/url
- http://"url
- wpenginebot@wpengine.comemail
- 131.0.0.0ipv4
- 103.215.74.26ipv4
- 103.215.75.66ipv4
- 103.215.75.19ipv4
- 103.168.67.253ipv4
- 51.195.39.149ipv4
- 103.168.66.101ipv4
- 51.195.39.150ipv4
- 140.174.186.101ipv4
- 45.148.10.18ipv4
- 45.148.10.247ipv4
- www.gravatar.comdomain