Investigating - ## Summary
A critical vulnerability chain in WordPress core, publicly known as **WP2Shell** (CVE-2026-63030 and CVE-2026-60137), allows unauthenticated attackers to fully compromise a WordPress website remotely. No login, plugin, or special configuration is required — a default WordPress installation on an affected version is exploitable.
Public exploit code is now in circulation and active exploitation has been observed in the wild. **If your site runs an affected version, you should treat updating as urgent.**
## Am I affected?
**Vulnerable — update urgently:**
- Running WordPress 7.0.0 or 7.0.1 → update to **7.0.2** or later (full remote code execution risk)
- Running WordPress 6.9.0 to 6.9.4 → update to **6.9.5** or later (full remote code execution risk)
- Running WordPress 6.8.0 to 6.8.5 → update to **6.8.6** or later (SQL injection risk)
**Already safe from this issue:**
- Running WordPress 7.0.2, 6.9.5, or 6.8.6 (or newer) → no action needed, you are patched
- Running a version below 6.8 → not affected by WP2Shell specifically, but these versions are end-of-life and carry other security risks, so we strongly recommend updating regardless
You can check your version from your WordPress dashboard under **Dashboard → Updates**, or in the **At a Glance** widget.
## What you need to do
1. **Take a backup first.** Before making any changes, take a full backup of your site files and database so you can roll back if anything goes wrong during the update.
2. **Update WordPress now.** From your WordPress dashboard, go to **Dashboard → Updates** and apply the available core update (7.0.2, 6.9.5, or 6.8.6 depending on your branch).
3. **Verify the update applied.** WordPress.org has enabled forced automatic updates for affected sites, but this does not reach every installation — particularly sites with automatic updates disabled. Do not assume you've been patched; confirm the version number in your dashboard.
4. **Update plugins and themes** while you're there.
5. **If you cannot update immediately**, contact our support team and we can discuss temporary mitigation options for your site.
## What is the risk if I don't update?
The vulnerability allows a completely anonymous attacker to execute code on your website. In practical terms, a successful attack can result in full site takeover, defacement, malware injection, data theft, or use of your site to attack others. Because exploit tools are now publicly available, unpatched sites are being actively scanned and targeted.
## Need help?
If you're unsure which version you're running, need assistance updating, or notice anything unusual on your site, please open a support ticket or contact our support team. We're happy to help.
Jul 20, 2026 - 09:46 UTC
A critical vulnerability chain in WordPress core, publicly known as **WP2Shell** (CVE-2026-63030 and CVE-2026-60137), allows unauthenticated attackers to fully compromise a WordPress website remotely. No login, plugin, or special configuration is required — a default WordPress installation on an affected version is exploitable.
Public exploit code is now in circulation and active exploitation has been observed in the wild. **If your site runs an affected version, you should treat updating as urgent.**
## Am I affected?
**Vulnerable — update urgently:**
- Running WordPress 7.0.0 or 7.0.1 → update to **7.0.2** or later (full remote code execution risk)
- Running WordPress 6.9.0 to 6.9.4 → update to **6.9.5** or later (full remote code execution risk)
- Running WordPress 6.8.0 to 6.8.5 → update to **6.8.6** or later (SQL injection risk)
**Already safe from this issue:**
- Running WordPress 7.0.2, 6.9.5, or 6.8.6 (or newer) → no action needed, you are patched
- Running a version below 6.8 → not affected by WP2Shell specifically, but these versions are end-of-life and carry other security risks, so we strongly recommend updating regardless
You can check your version from your WordPress dashboard under **Dashboard → Updates**, or in the **At a Glance** widget.
## What you need to do
1. **Take a backup first.** Before making any changes, take a full backup of your site files and database so you can roll back if anything goes wrong during the update.
2. **Update WordPress now.** From your WordPress dashboard, go to **Dashboard → Updates** and apply the available core update (7.0.2, 6.9.5, or 6.8.6 depending on your branch).
3. **Verify the update applied.** WordPress.org has enabled forced automatic updates for affected sites, but this does not reach every installation — particularly sites with automatic updates disabled. Do not assume you've been patched; confirm the version number in your dashboard.
4. **Update plugins and themes** while you're there.
5. **If you cannot update immediately**, contact our support team and we can discuss temporary mitigation options for your site.
## What is the risk if I don't update?
The vulnerability allows a completely anonymous attacker to execute code on your website. In practical terms, a successful attack can result in full site takeover, defacement, malware injection, data theft, or use of your site to attack others. Because exploit tools are now publicly available, unpatched sites are being actively scanned and targeted.
## Need help?
If you're unsure which version you're running, need assistance updating, or notice anything unusual on your site, please open a support ticket or contact our support team. We're happy to help.
Jul 20, 2026 - 09:46 UTC
Update - We’re still actively investigating this issue. We’ve confirmed it was caused by an updated module within the billing control panel. Resolving this will require assistance from our development team, and at this time, we expect a full resolution within the next few weeks. We appreciate your continued patience while we work toward a permanent fix.
We still recommend contacting our billing team at billing@hostek.com for any questions.
Feb 04, 2026 - 22:22 UTC
We still recommend contacting our billing team at billing@hostek.com for any questions.
Feb 04, 2026 - 22:22 UTC
Identified - We are aware of a complication affecting our ability to take payments using PayPal.
We're in discussions with our vendor, in the mean time you can make payment by selecting "pay by card" using our Stripe provider.
We do apologize for any inconvenience this may cause.
Please contact our billing team using billing@hostek.com if you have any questions.
Jan 21, 2026 - 15:47 UTC
We're in discussions with our vendor, in the mean time you can make payment by selecting "pay by card" using our Stripe provider.
We do apologize for any inconvenience this may cause.
Please contact our billing team using billing@hostek.com if you have any questions.
Jan 21, 2026 - 15:47 UTC
About This Site
Hostek provides Cloud Server hosting for businesses of all sizes. This page outlines the status of Hostek provided services.
Network Infrastructure
Operational
STL Region
Operational
REA Region
Operational
ASH Region
Operational
ATL Region
Operational
ENF Region
Operational
ColdFusion Services
Operational
Shared Services
Operational
Customer Support
Operational
Client Portal
Operational
External Internet Service
Operational
Common 3rd-Party Services
Operational
Cloudflare DNS Root Servers
Operational
Cloudflare Cloudflare Authoritative DNS
Operational
Intercom Email
Operational
Intercom Chats and Posts
Operational
Operational
Degraded Performance
Partial Outage
Major Outage
Maintenance
Major outage
Partial outage
No downtime recorded on this day.
No data exists for this day.
had a major outage.
had a partial outage.
