SOCRadar has launched a free wp2shell checker to help organizations quickly determine whether their WordPress websites may be exposed to CVE-2026-63030, a critical remote code execution vulnerability affecting recent WordPress versions.
The tool allows users to enter a domain and assess potential exposure without manually reviewing WordPress versions or configurations—particularly useful for organizations managing large numbers of public-facing, subsidiary, staging or forgotten websites.
The checker is designed to help security teams:
- Quickly identify potentially exposed WordPress assets
- Verify whether automatic WordPress updates were successfully applied
- Prioritize vulnerable or overlooked sites for remediation
- Reduce the risk posed by unknown WordPress installations across the external attack surface
SOCRadar has also published a supporting technical analysis explaining how the wp2shell vulnerability chain can lead to unauthenticated remote code execution, which WordPress versions are affected and what defenders should look for in their logs.
You can access the checker and analysis here:
https://socradar.io/blog/wp2shell-wordpress-rce-cve-2026-63030/



WP Botnet Master – How a Security Researcher’s Paid Course Built a 2.1-Million-Credential WordPress Botnet
Posted in Commentary with tags SOCRadar on July 24, 2026 by itnerdToday, SOCRadar published new research WP Botnet Master: How a Security Researcher’s Paid Course Built a 2.1-Million-Credential WordPress Botnet.
On 13 July 2026, SOCRadar Researchers recovered the complete toolkit behind a distributed WordPress brute-force operation the operator called “WP Botnet Master.” We expected to be looking at the work of a single skilled attacker. What we found was a graduation project.
The server they pulled apart did not belong to a lone hacker. It belonged to a paying student of a structured, commercial “training” program run by a WordPress security researcher who sells cybercrime as a course – complete with a curriculum, a lab blueprint, a community, and an AI-assisted workflow that lets students build and run credential-harvesting botnets with almost no skill of their own.
One student, acting alone, harvested 2,118,764 WordPress administrator credentials from 606,591 domains across 100 countries. There are roughly 295 more people in the community that trained him. The botnet is a symptom. The academy is the disease.
Key Points:
This is scalable, repeatable, and deliberately deniable cybercrime. Each of the ~295 community members is a candidate to reproduce the full operation – and an English-language edition of the course is already in development.
To view the full report, please see WP Botnet Master: How a Security Researcher’s Paid Course Built a 2.1-Million-Credential WordPress Botnet
Leave a comment »