Navigation indicator

Critical WordPress Core Vulnerability (wp2shell) – What You Need to Know

July 20, 2026

On July 17th, the WordPress Security Team released urgent patches for wp2shell, considered the worst security vulnerability in the WordPress core in nearly a decade.

Because this vulnerability exists in the WordPress application core—affecting hundreds of millions of sites across the global internet—we want to outline what took place, explain its impact and share the immediate steps we took across our infrastructure to keep your sites safe.

What Makes wp2shell So Serious?

  • Widespread Global Impact: This is a software vulnerability within the WordPress core codebase affecting hundreds of millions of websites worldwide.
  • No Extras Required: Unlike most security issues that target specific plugins or themes, this vulnerability exists directly in the main WordPress core software. It requires no plugins, no themes or even logged-in access to exploit.
  • Affected Versions: The vulnerability impacts WordPress core release branches 6.8, 6.9 and 7.0.
  • Immediate Threat: Automated exploit attempts began targeting vulnerable sites globally within hours of public disclosure on July 17th.

Actions We Have Already Taken

To protect client websites and maintain environment integrity, our team took immediate action upon the official patch release on July 17th:

  1. WordPress Care & Maintenance Subscribers: All client websites subscribed to our WordPress Care & Maintenance plan were audited and updated immediately.
  2. Installatron Automatic Updates: Sites configured with automatic core updates enabled in Installatron were automatically patched to safe versions that night.
  3. Web Application Firewall Protection: We deployed server-level firewall rules across our platform to intercept and block known exploit attempts.

What You Need to Do

While our active firewall rules block incoming attack attempts, updating your WordPress software to a patched release is the only permanent fix.

  • If your WordPress site is already updated to version 6.8.6, 6.9.5 or 7.0.2 (or higher):
    You are fully protected! No further action is required.
  • If your site is running a vulnerable version of the 6.8, 6.9 or 7.0 branch:
    Please update your site immediately. You can do this easily in one of two ways:
    • Option 1: Log in to your cPanel control panel, open Installatron, locate your WordPress site and click the update button.
    • Option 2: Log in directly to your WordPress Admin Dashboard (/wp-admin), navigate to Dashboard > Updates, and click Update Now.

If you have any questions or need assistance verifying whether your site is running a safe version, please open a support ticket with our technical support team—we are here to help!

Comments

Leave a Reply