WP2Shell RCE

FortiGuard Labs continues to detect exploitation attempts targeting the WP2Shell attack chain (CVE-2026-63030 and CVE-2026-60137), a critical unauthenticated remote code execution (RCE) vulnerability affecting WordPress Core. Telemetry collected over the past seven days shows the highest volume of blocked attacks originating from or targeting Poland, Australia, Japan, the United States, and Turkey.