INTEL_REPORT
The Hacker News · published 7/21/2026, 8:59:30 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. "By the early hours of Saturday morning (UTC), successful exploitation was already well WordPress w…
https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html
sha256:537f713a01b45b5d289f5d3f1e0a1ad90289a93bfb125de59cdf64345f2d8bd2
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.