← Back to Feed

PoC Published for CVE-2026-60137: Wp2shell-ioc-scanner

CVE-2026-60137

August 1, 2026 · GitHub · Severity: CRITICAL

Proof of Concept exploit published on GitHub: Wp2shell-ioc-scanner. Defensive WordPress incident-response plugin for the "wp2shell" attack chain (CVE-2026-60137 / CVE-2026-63030): detects shadow-admin IOCs and deletes a selected account in a controlled, logged way.

Defensive WordPress incident-response plugin for the "wp2shell" attack chain (CVE-2026-60137 / CVE-2026-63030): detects shadow-admin IOCs and deletes a selected account in a controlled, logged way. Does not remove malware. Repository: https://github.com/michael-kanda/Wp2shell-ioc-scanner Stars: 0 Created: 2026-08-01T07:59:06Z

Key Takeaways

  • A public proof-of-concept exploit has been published for CVE-2026-60137, demonstrating how the vulnerability can be exploited.
  • Organizations using affected products should review the published PoC and apply vendor patches immediately.
  • Proof of Concept exploit published on GitHub: Wp2shell-ioc-scanner. Defensive WordPress incident-response plugin for the "wp2shell" attack chain (CVE-. Proof-of-concept code lowers the barrier for exploitation — attackers and security tools alike can leverage it.
☕ Buy a Coffee