Vulnerabilities · 54 days ago
WordPress PoCs Leave Artifacts as Windmill Is Hit The break is no longer just a vulnerable endpoint. Public wp2shell PoCs are now leaving repeatable host artifacts on WordPress systems, and Windmill is still seeing live exploitation, so patching alone is not enough to tell you whether a box is already compromised.
VulnCheck says Windmill CVE-2026-29059 is being actively used against the get_log_file endpoint, and Windmill fixed it in 1.603.3 . On the WordPress side, CISA added CVE-2026-60137 and CVE-2026-63030 to KEV, and telemetry from public PoCs shows shells and fake plugin directories appearing on disk on affected hosts.
The practical shift is forensic, not just operational: request logs and network indicators can vary, but the host often gives the compromise away. For Windmill, the file-read can become control-plane access if SUPERADMIN_SECRET is present; for WordPress, internet-facing systems may already show local signs of attacker control even before defenders finish triage.
NVD KEV
Known exploited · CISA KEV
CVSS 5.9 MEDIUM: wordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the… EPSS 78% (100th percentile).
CISA federal remediation date Aug 4
NVD KEV
Known exploited · CISA KEV
CVSS 7.5 HIGH: wordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue…
CISA federal remediation date Jul 24
CVE-2026-29059 NVD KEV
EPSS 3% (86th percentile).
Timeline Sources 20 sources covering this story
Elastic Security Labs Jul 22
wp2shell: detecting WordPress pre-auth RCE end-to-end — Elastic Security Labs
We ran the wp2shell WordPress RCE chain end-to-end with Elastic Defend.
The Hacker News Jul 22
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
VulnCheck says attackers are exploiting Windmill CVE-2026-29059 to read server files, with about 170 vulnerable systems exposed in 24 countries.
Help Net Security Jul 21
SonicWall SMA zero-days were exploited weeks before disclosure - Help Net Security
CVE-2026-15409 and CVE-2026-15410 were exploited since June 22, 2026, allowing threat actors to install custom malware.
The Hacker News Jul 21
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and malicious plugins.
The Register Security Jul 21
Attackers pummel critical WordPress vuln to create all sorts of mischief
Plus dozens of PoCs in the public domain
Dark Reading Jul 20
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
Attackers are chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.
SANS ISC Jul 20
WordPress Exploitation Underway (CVE-2026-63030) - SANS ISC
WordPress Exploitation Underway (CVE-2026-63030), Author: Johannes Ullrich
BleepingComputer Jul 20
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances.
Wiz Research Jul 20
Exploitation in the Wild of wp2shell | Wiz Blog
Wiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137).
TechCrunch Security Jul 20
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk | TechCrunch
Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.
SecurityWeek Jul 20
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.
The Hacker News Jul 20
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
This recap covers exploited flaws, exposed systems, malware campaigns, weak defaults, and the security gaps demanding attention.
Entities CVE-2026-63030 CVE-2026-60137 CVE-2026-29059 Part of the PlainSec briefing for 2026-07-20
Editions Related stories
Vulnerabilities · 54 days ago
WordPress PoCs Leave Artifacts as Windmill Is Hit The break is no longer just a vulnerable endpoint. Public wp2shell PoCs are now leaving repeatable host artifacts on WordPress systems, and Windmill is still seeing live exploitation, so patching alone is not enough to tell you whether a box is already compromised.
VulnCheck says Windmill CVE-2026-29059 is being actively used against the get_log_file endpoint, and Windmill fixed it in 1.603.3 . On the WordPress side, CISA added CVE-2026-60137 and CVE-2026-63030 to KEV, and telemetry from public PoCs shows shells and fake plugin directories appearing on disk on affected hosts.
The practical shift is forensic, not just operational: request logs and network indicators can vary, but the host often gives the compromise away. For Windmill, the file-read can become control-plane access if SUPERADMIN_SECRET is present; for WordPress, internet-facing systems may already show local signs of attacker control even before defenders finish triage.
NVD KEV
Known exploited · CISA KEV
CVSS 5.9 MEDIUM: wordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the… EPSS 78% (100th percentile).
CISA federal remediation date Aug 4
NVD KEV
Known exploited · CISA KEV
CVSS 7.5 HIGH: wordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue…
CISA federal remediation date Jul 24
CVE-2026-29059 NVD KEV
EPSS 3% (86th percentile).
Timeline Sources 20 sources covering this story
Elastic Security Labs Jul 22
wp2shell: detecting WordPress pre-auth RCE end-to-end — Elastic Security Labs
We ran the wp2shell WordPress RCE chain end-to-end with Elastic Defend.
The Hacker News Jul 22
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
VulnCheck says attackers are exploiting Windmill CVE-2026-29059 to read server files, with about 170 vulnerable systems exposed in 24 countries.
Help Net Security Jul 21
SonicWall SMA zero-days were exploited weeks before disclosure - Help Net Security
CVE-2026-15409 and CVE-2026-15410 were exploited since June 22, 2026, allowing threat actors to install custom malware.
The Hacker News Jul 21
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
Attackers are exploiting two WordPress flaws as wp2shell, chaining them for unauthenticated RCE and deploying web shells and malicious plugins.
The Register Security Jul 21
Attackers pummel critical WordPress vuln to create all sorts of mischief
Plus dozens of PoCs in the public domain
Dark Reading Jul 20
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
Attackers are chaining together CVE-2026-60137 and CVE-2026-63030 to lob exploit attempts against one of the largest attack surfaces on the Internet.
SANS ISC Jul 20
WordPress Exploitation Underway (CVE-2026-63030) - SANS ISC
WordPress Exploitation Underway (CVE-2026-63030), Author: Johannes Ullrich
BleepingComputer Jul 20
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances.
Wiz Research Jul 20
Exploitation in the Wild of wp2shell | Wiz Blog
Wiz Research has identified exploitation of "wp2shell", a critical pre-auth RCE vulnerability chain impacting WordPress Core (CVE-2026-63030 & CVE-2026-60137).
TechCrunch Security Jul 20
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk | TechCrunch
Two critical security flaws in WordPress’ software have given hackers the chance to remotely take over tens of millions of websites, according to an estimate by a cybersecurity researcher.
SecurityWeek Jul 20
SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch
The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.
The Hacker News Jul 20
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
This recap covers exploited flaws, exposed systems, malware campaigns, weak defaults, and the security gaps demanding attention.
Entities CVE-2026-63030 CVE-2026-60137 CVE-2026-29059 Part of the PlainSec briefing for 2026-07-20
Editions Related stories