Attackers are actively exploiting two recently disclosed WordPress vulnerabilities (CVE-2026-60137 and CVE-2026-63030) in combination to gain remote control of WordPress sites at massive scale, with exploitation beginning just days after the vulnerabiliti
Read the full article: https://www.darkreading.com/cyberattacks-data-breaches/wp2shell-millions-wordpress-sites-remote-takeover