Exploitation of the WordPress attack chain known as "wp2shell" is expanding, with attackers reportedly increasing scans for vulnerable websites after exploit details became public. The campaign centers on two critical WordPress weaknesses that can be linked together to achieve unauthenticated remote code execution.

When the flaws are successfully chained, an attacker can gain deep control over a targeted site without logging in first. From there, the activity described includes deploying web shells and installing malicious plugins, both of which can help maintain access and further compromise the environment.

The rise in mass scanning suggests the threat is moving beyond targeted abuse and into broader, automated probing of exposed WordPress instances. That pattern often follows the release of public exploit code, as more threat actors gain the ability to test large numbers of sites for the same weakness.

For WordPress administrators, the development highlights the risk posed by unpatched or otherwise exposed installations. Any site affected by the wp2shell chain could face full takeover, making this a serious website security issue as exploitation activity continues to grow.