WordPress wp2shell and ServiceNow AI Flaws Under Active Attack [Prime Cyber Insights]
This is Prime Cyber Insights for July 21st, 2026. <br/><i>acting_description:</i> professional, steady, concise <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.2 Today, we're tracking a significant escalation in unauthenticated remote code execution exploits hitting core infrastructure. <br/><i>acting_description:</i> engaged, measured, informative <i>speed:</i> 1.0 <i>trailing_silence:</i> 0.3 Leading the briefing is wp2shell, a critical vulnerability chain in WordPress. The Hacker News reports that CVE 2026 63030 and CVE 2026 60137 are being combined to achieve unauthenticated RCE. Researchers at watchTowr say exploitation was well underway by Saturday, utilizing public exploit code to exfiltrate credentials and deploy backdoors. <br/><i>acting_description:</i> analytical, direct, authoritative <i>speed:</i> 0.98 <i>trailing_silence:</i> 0.4 Aaron, the telemetry is concerning. KEVIntel has linked 13 unique IPs globally to these attempts, and Wiz suggests that initially, 60 percent of organizations using WordPress had at least one vulnerable instance. This isn't just about plugins

