THREATOPS
THREAT OPSThreat News › wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution

wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution

medelastic_securityPublished 2026-07-23

<p>On July 17, 2026, <a href="https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core">Searchlight Cyber</a> disclosed <code>wp2shell</code>, a pre-authentication remote code execution chain in WordPress Core (<a href="https://nvd.nist.gov/vuln/detail/CVE-2026-63030">CVE-2026-63030</a>, <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-60137">CVE-2026-60137</a>). Proo

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.elastic.co/security-labs/wp2shell-wordpress-rce-detection-elastic-defend