← Back to Feed
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
CVE-2026-60137CVE-2026-63030
July 20, 2026 · Dark Reading · Severity: HIGH
The WP2Shell attack chain exploits two vulnerabilities — CVE-2026-0098 and CVE-2026-03102 — to compromise millions of WordPress sites with remote code execution capabilities. By chaining these flaws, attackers can bypass authentication, upload arbitrary files, and execute PHP code on vulnerable WordPress installations without needing valid credentials. The massive install base of WordPress means that millions of sites are potentially affected, and automated scanning tools are likely already probing for vulnerable instances, making patching urgent for site administrators who have not yet applied updates.
Key Takeaways
- WP2Shell chains CVE-2026-0098 and CVE-2026-03102 to achieve remote code execution on WordPress sites.
- The exploit bypasses authentication entirely, requiring no valid credentials to compromise target sites.
- Millions of WordPress installations are potentially vulnerable given the platform's market dominance.