SiteCountry Blog
  • Home
  • About
Sign in Subscribe

CVE-2026-60137

Developer reviewing server logs on a laptop next to a WordPress dashboard on a second monitor while investigating a security

WordPress wp2shell Exploit Drives a New Wave of Mass Scanning

Two newly disclosed WordPress flaws are being chained into an unauthenticated remote code execution bug dubbed wp2shell. Public exploit code has triggered mass scanning, putting unpatched sites at serious risk.
SiteCountry Team Jul 27, 2026
Editor reviewing a WordPress core security update on a laptop while exploit traffic logs scroll in a terminal window in the

Ninety Minutes to Weaponized: Inside the WordPress Core RCE Race

A pre-auth SQL injection and a REST batch route confusion in WordPress core were chained into remote code execution. Attackers hit the internet roughly ninety minutes after the fix shipped, and the campaign has not slowed down.
SiteCountry Team Jul 27, 2026

Subscribe to SiteCountry Blog

Don't miss out on the latest news. Sign up now to get access to the library of members-only articles.
  • Sign up
SiteCountry Blog © 2026. Powered by Ghost