wp2shell: Why Patching WordPress Just Became Urgent

A serious WordPress security flaw is being actively exploited right now, and if you run a WordPress website it is worth five minutes of your attention today. It is also a textbook example of why keeping software patched is not optional.

What happened

Security researchers have disclosed two flaws in WordPress core that can be chained together into a single attack, nicknamed “wp2shell”. Tracked as CVE-2026-63030 and CVE-2026-60137, the combined chain lets an attacker take complete control of a vulnerable site without needing to log in. That is what security people call an unauthenticated remote code execution flaw, and it is the first critical one in WordPress core in nearly a decade.

The details, in plain terms:

  • Affected versions: WordPress 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. A related database flaw also affects 6.8.0 to 6.8.5.
  • Fixed in: WordPress 6.9.5 and 7.0.2, and 6.8.6 for the older branch. Updating is the fix.
  • Status: Disclosed on 17 July 2026. Working exploit code is now public, and on 21 July the flaws were added to the US CISA Known Exploited Vulnerabilities list, which confirms they are being exploited in the wild.

Why it matters to your business

WordPress powers a large share of the world’s business websites, so this affects a lot of ordinary companies, not just big targets. “Unauthenticated” is the important word here: an attacker needs no password and no account. They simply find a vulnerable site and take it over.

Once in, an attacker can steal customer data, deface or take down your site, inject scam or malware content that damages your reputation, or use your server as a springboard to attack others. Because working exploit code is public and the flaw is on the actively-exploited list, automated tools are already scanning the internet for unpatched sites. This is not a “maybe next month” risk. Unpatched sites are being found and hit now.

What we have already done for our clients

If System Force IT manages your systems, there is nothing for you to do. We actively patch and monitor our clients’ systems through our own ClearSignal management platform, so critical updates like this one are applied promptly and verified, rather than left to chance or to someone remembering to click “update”. We hold ourselves to the same standard: our own website runs on WordPress and is patched and monitored the same way.

This is the quiet value of managed IT support and maintenance. The dangerous gap for most businesses is not knowing a flaw exists, it is the days or weeks between a patch being released and someone actually applying it. Removing that gap is exactly what we do.

What to check if no one is managing this for you

If your website is not actively managed, please take a few minutes today:

  1. Check your WordPress version. Log in and look at Dashboard, then Updates. If you are on 6.9.0 to 6.9.4 or 7.0.0 to 7.0.1, you are vulnerable.
  2. Update immediately to 6.9.5 or 7.0.2, or 6.8.6 on the 6.8 branch. Take a backup first, then apply the update. Turning on automatic core updates is sensible going forward.
  3. If you cannot update straight away, a reputable security plugin or web application firewall can help block attacks in the meantime, but updating is the only real fix.
  4. Look for signs of trouble such as unexpected administrator accounts, unfamiliar files, or content you did not add. If anything looks wrong, treat the site as compromised and get expert help.

The broader lesson is one we return to often: the businesses that stay safe are not the ones that never face threats, they are the ones that patch quickly and consistently. If keeping on top of updates across your website, computers and servers feels like a job nobody quite owns, that is precisely the problem we solve. Our IT and cyber security services and managed IT support keep the whole estate patched and monitored, so a headline like this one becomes something you read about rather than something that happens to you.

Not sure where you stand? Book a free IT audit and we will check it for you.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name