Critical WordPress WP2Shell Vulnerability Under Active Attack
A newly discovered WordPress security flaw allows hackers to execute malicious code without needing any plugins, putting thousands of websites at risk.
WordPress users have been cautioned about an alarming threat to their websites called the WP2Shell vulnerability (CVE-2026-63030) that enables the execution of malware on websites running WordPress without having any third-party plug-ins.
The flaw is being exploited by hackers at an active rate, and thus, requires immediate attention from website owners. Hackers are using it to steal data, manipulate website information, create administrator accounts, or even take control of the website.
Cloudflare along with other security firms has updated its Web Application Firewall to block such attacks. But as a website owner, it is not wise to solely depend on security applications. Installing the latest version of WordPress is the most secure method to avoid such attacks.
If you own a WordPress website, then it is advised to install the latest update. Apart from that, backing up the website, setting a strong password, enabling multi-factor authentication, or installing a reliable security plugin will minimize the chances of a cybersecurity attack.
One of the simplest ways of securing your website is by staying updated.




