TI Mindmap HUB
Threat Intelligence Report

wp2shell hits WordPress: detecting pre-auth RCE from plugin drop to command execution

๐Ÿ“… July 22, 2026 ๐Ÿ“ฐ www.elastic.co ๐Ÿ” 2 CVE(s) referenced

The wp2shell exploit chain enables pre-authenticated remote code execution on default WordPress installs via a REST API vulnerability, with public PoCs already driving widespread attacks, but defenders can reliably detect and stop exploitation by patching promptly and monitoring for telltale web server-to-shell behavior and specific file and process activity.

vendor
CVE-2026-63030, CVE-2026-60137

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

๐Ÿ” Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

๐Ÿ“Š Visual Mindmap
๐ŸŽฏ IOC Extraction
โš”๏ธ MITRE ATT&CK TTPs
๐Ÿ“ฆ STIX 2.1 Bundle