WordPress Wp2shell Webshell Plugin Access

Rule Info

Name
WordPress Wp2shell Webshell Plugin Access
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects post-exploitation access to the wp2shell webshell plugin dropped after successful exploitation of CVE-2026-63030 and CVE-2026-60137. After the pre-auth SQLi-to-admin bridge is established, the attacker can upload a malicious plugin (wp2shell) to the target WordPress instance. At this phase, the attacker accesses the webshell for command execution and persistence.
Date
2026-07-19 00:00:00
Modified
None
Id
c9e6f412-3d50-4f7e-bf94-5b6c7d8e9f0a
Tags
attack.execution attack.persistence attack.t1505.003 cve.2026-63030 cve.2026-60137 detection.emerging-threats
Type
Community Rule

Rule History

Author
Title
Date
Commit
Swachchhanda Shrawan Poudel
Merge PR #6155 from @swachchhanda000 - Add WordPress Wp2shell Detections
2026-07-20