Security Advisory: Critical WordPress Vulnerability ("WP2Shell") — Update Immediately

Incident Report for Hostek

Investigating

## Summary
A critical vulnerability chain in WordPress core, publicly known as **WP2Shell** (CVE-2026-63030 and CVE-2026-60137), allows unauthenticated attackers to fully compromise a WordPress website remotely. No login, plugin, or special configuration is required — a default WordPress installation on an affected version is exploitable.

Public exploit code is now in circulation and active exploitation has been observed in the wild. **If your site runs an affected version, you should treat updating as urgent.**

## Am I affected?
**Vulnerable — update urgently:**
- Running WordPress 7.0.0 or 7.0.1 → update to **7.0.2** or later (full remote code execution risk)
- Running WordPress 6.9.0 to 6.9.4 → update to **6.9.5** or later (full remote code execution risk)
- Running WordPress 6.8.0 to 6.8.5 → update to **6.8.6** or later (SQL injection risk)

**Already safe from this issue:**
- Running WordPress 7.0.2, 6.9.5, or 6.8.6 (or newer) → no action needed, you are patched
- Running a version below 6.8 → not affected by WP2Shell specifically, but these versions are end-of-life and carry other security risks, so we strongly recommend updating regardless

You can check your version from your WordPress dashboard under **Dashboard → Updates**, or in the **At a Glance** widget.

## What you need to do
1. **Take a backup first.** Before making any changes, take a full backup of your site files and database so you can roll back if anything goes wrong during the update.
2. **Update WordPress now.** From your WordPress dashboard, go to **Dashboard → Updates** and apply the available core update (7.0.2, 6.9.5, or 6.8.6 depending on your branch).
3. **Verify the update applied.** WordPress.org has enabled forced automatic updates for affected sites, but this does not reach every installation — particularly sites with automatic updates disabled. Do not assume you've been patched; confirm the version number in your dashboard.
4. **Update plugins and themes** while you're there.
5. **If you cannot update immediately**, contact our support team and we can discuss temporary mitigation options for your site.

## What is the risk if I don't update?
The vulnerability allows a completely anonymous attacker to execute code on your website. In practical terms, a successful attack can result in full site takeover, defacement, malware injection, data theft, or use of your site to attack others. Because exploit tools are now publicly available, unpatched sites are being actively scanned and targeted.

## Need help?
If you're unsure which version you're running, need assistance updating, or notice anything unusual on your site, please open a support ticket or contact our support team. We're happy to help.
Posted Jul 20, 2026 - 09:46 UTC
This incident affects: Shared Services.