- Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk TechCrunch
- ‘WP2Shell’ Opens Millions of WordPress Sites to Remote Takeover Dark Reading
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More The Hacker News
- What happens if you visit a WordPress site hacked through wp2shell? Malwarebytes
- Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities The Cloudflare Blog
- Attackers pummel critical WordPress vuln to create all sorts of mischief The Register
- CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core Rapid7
- Critical wp2shell WordPress flaws exploited to install webshells BleepingComputer
- WP2Shell WordPress Vulnerabilities Exploited in the Wild SecurityWeek