WordPress Wp2shell Webshell Plugin Access
Description
Detects post-exploitation access to the wp2shell webshell plugin dropped after successful exploitation of CVE-2026-63030 and CVE-2026-60137. After the pre-auth SQLi-to-admin bridge is established, the attacker can upload a malicious plugin (wp2shell) to the target WordPress instance. At this phase, the attacker accesses the webshell for command execution and persistence.
Query · sigma
selection: cs-uri-stem|contains: /wp-content/plugins/wp2shell_ filter_optional_null_query: cs-uri-query: null condition: selection and not 1 of filter_optional_*
Known false positives
- Unlikely