Investigating - ## Summary
A critical vulnerability chain in WordPress core, publicly known as **WP2Shell** (CVE-2026-63030 and CVE-2026-60137), allows unauthenticated attackers to fully compromise a WordPress website remotely. No login, plugin, or special configuration is required — a default WordPress installation on an affected version is exploitable.

Public exploit code is now in circulation and active exploitation has been observed in the wild. **If your site runs an affected version, you should treat updating as urgent.**

## Am I affected?
**Vulnerable — update urgently:**
- Running WordPress 7.0.0 or 7.0.1 → update to **7.0.2** or later (full remote code execution risk)
- Running WordPress 6.9.0 to 6.9.4 → update to **6.9.5** or later (full remote code execution risk)
- Running WordPress 6.8.0 to 6.8.5 → update to **6.8.6** or later (SQL injection risk)

**Already safe from this issue:**
- Running WordPress 7.0.2, 6.9.5, or 6.8.6 (or newer) → no action needed, you are patched
- Running a version below 6.8 → not affected by WP2Shell specifically, but these versions are end-of-life and carry other security risks, so we strongly recommend updating regardless

You can check your version from your WordPress dashboard under **Dashboard → Updates**, or in the **At a Glance** widget.

## What you need to do
1. **Take a backup first.** Before making any changes, take a full backup of your site files and database so you can roll back if anything goes wrong during the update.
2. **Update WordPress now.** From your WordPress dashboard, go to **Dashboard → Updates** and apply the available core update (7.0.2, 6.9.5, or 6.8.6 depending on your branch).
3. **Verify the update applied.** WordPress.org has enabled forced automatic updates for affected sites, but this does not reach every installation — particularly sites with automatic updates disabled. Do not assume you've been patched; confirm the version number in your dashboard.
4. **Update plugins and themes** while you're there.
5. **If you cannot update immediately**, contact our support team and we can discuss temporary mitigation options for your site.

## What is the risk if I don't update?
The vulnerability allows a completely anonymous attacker to execute code on your website. In practical terms, a successful attack can result in full site takeover, defacement, malware injection, data theft, or use of your site to attack others. Because exploit tools are now publicly available, unpatched sites are being actively scanned and targeted.

## Need help?
If you're unsure which version you're running, need assistance updating, or notice anything unusual on your site, please open a support ticket or contact our support team. We're happy to help.

Jul 20, 2026 - 09:46 UTC
Update - We’re still actively investigating this issue. We’ve confirmed it was caused by an updated module within the billing control panel. Resolving this will require assistance from our development team, and at this time, we expect a full resolution within the next few weeks. We appreciate your continued patience while we work toward a permanent fix.

We still recommend contacting our billing team at billing@hostek.com for any questions.

Feb 04, 2026 - 22:22 UTC
Identified - We are aware of a complication affecting our ability to take payments using PayPal.
We're in discussions with our vendor, in the mean time you can make payment by selecting "pay by card" using our Stripe provider.

We do apologize for any inconvenience this may cause.
Please contact our billing team using billing@hostek.com if you have any questions.

Jan 21, 2026 - 15:47 UTC

About This Site

Hostek provides Cloud Server hosting for businesses of all sizes. This page outlines the status of Hostek provided services.

Network Infrastructure Operational
90 days ago
99.95 % uptime
Today
STL Region Operational
90 days ago
99.79 % uptime
Today
REA Region Operational
90 days ago
100.0 % uptime
Today
ASH Region Operational
90 days ago
100.0 % uptime
Today
ATL Region Operational
90 days ago
100.0 % uptime
Today
ENF Region Operational
90 days ago
100.0 % uptime
Today
ColdFusion Services Operational
Shared Services Operational
Customer Support Operational
Client Portal Operational
External Internet Service Operational
Common 3rd-Party Services Operational
Cloudflare DNS Root Servers Operational
Cloudflare Cloudflare Authoritative DNS Operational
Intercom Email Operational
Intercom Chats and Posts Operational
Operational
Degraded Performance
Partial Outage
Major Outage
Maintenance
Major outage
Partial outage
No downtime recorded on this day.
No data exists for this day.
had a major outage.
had a partial outage.
Jul 22, 2026

No incidents reported today.

Jul 21, 2026

No incidents reported.

Jul 20, 2026

Unresolved incident: Security Advisory: Critical WordPress Vulnerability ("WP2Shell") — Update Immediately.

Jul 19, 2026

No incidents reported.

Jul 18, 2026

No incidents reported.

Jul 17, 2026

No incidents reported.

Jul 16, 2026

No incidents reported.

Jul 15, 2026

No incidents reported.

Jul 14, 2026

No incidents reported.

Jul 13, 2026
Completed - Maintenance on the uplinks in Reading is complete and all connected paths look to be functioning nominally. If you have questions or any issue post-maintenance please contacts us at support with any inquiries.
Jul 13, 13:33 UTC
In progress - Scheduled maintenance is currently in progress. We will provide updates as necessary.
Jul 13, 13:00 UTC
Scheduled - Out upstream provider will be performing essential maintenance on our network infrastructure located in Reading, UK This maintenance is crucial to enhance the reliability and performance of our network services, will be brief, and will be monitoring their progress.
Jul 12, 22:34 UTC
Jul 12, 2026

No incidents reported.

Jul 11, 2026

No incidents reported.

Jul 10, 2026

No incidents reported.

Jul 9, 2026

No incidents reported.

Jul 8, 2026

No incidents reported.