THREAT OPS › Threat News › wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution
wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution
<p>On July 17, 2026, <a href="https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core">Searchlight Cyber</a> disclosed <code>wp2shell</code>, a pre-authentication remote code execution chain in WordPress Core (<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-63030">CVE-2026-63030</a>, <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-60137">CVE-2026-60137</a>). Proo
MITRE ATT&CK techniques
- System Owner/User DiscoveryT1033
- System Information DiscoveryT1082
- Exploit Public-Facing ApplicationT1190
- Vulnerability ScanningT1595.002
- Web ShellT1505.003
- Command and Scripting InterpreterT1059
- Server Software ComponentT1505
- Exploit Public-Facing ApplicationAML.T0049
- Command and Scripting InterpreterAML.T0050
- Reverse ShellAML.T0072
Indicators of compromise
- a8602190dc5e6ace08493272ee953f9fefd9eae3sha1
- e45a6518f6478eb91623feb1cfac63e4e2f01fd3sha1
- CVE-2026-63030cve
- CVE-2026-60137cve
- https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-coreurl
- https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/url
- https://wp2shell.com/url
- https://isc.sans.edu/forums/diary/WordPress+Exploitation+Underway+CVE202663030/33168/url