The break is no longer just a vulnerable endpoint. Public wp2shell PoCs are now leaving repeatable host artifacts on WordPress systems, and Windmill is still seeing live exploitation, so patching alone is not enough to tell you whether a box is already compromised.
VulnCheck says Windmill CVE-2026-29059 is being actively used against the get_log_file endpoint, and Windmill fixed it in 1.603.3. On the WordPress side, CISA added CVE-2026-60137 and CVE-2026-63030 to KEV, and telemetry from public PoCs shows shells and fake plugin directories appearing on disk on affected hosts.
The practical shift is forensic, not just operational: request logs and network indicators can vary, but the host often gives the compromise away. For Windmill, the file-read can become control-plane access if SUPERADMIN_SECRET is present; for WordPress, internet-facing systems may already show local signs of attacker control even before defenders finish triage.