
The Hacker News
July 21, 20261 min read
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. "By the early hours of Saturday morning (UTC), successful exploitation was already well
Read what's here, then head to the original whenever you're ready - never required.
Continue Reading on The Hacker NewsFakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
The Hacker News July 20, 2026