Navigation indicator

Critical WordPress Core Vulnerability (wp2shell) – What You Need to Know

July 20, 2026

On July 17th, the WordPress Security Team released urgent patches for wp2shell, considered the worst security vulnerability in the WordPress core in nearly a decade.

Because this vulnerability exists in the WordPress application core—affecting hundreds of millions of sites across the global internet—we want to outline what took place, explain its impact and share the immediate steps we took across our infrastructure to keep your sites safe.

What Makes wp2shell So Serious?

  • Widespread Global Impact: This is a software vulnerability within the WordPress core codebase affecting hundreds of millions of websites worldwide.
  • No Extras Required: Unlike most security issues that target specific plugins or themes, this vulnerability exists directly in the main WordPress core software. It requires no plugins, no themes or even logged-in access to exploit.
  • Affected Versions: The vulnerability impacts WordPress core release branches 6.8, 6.9 and 7.0.
  • Immediate Threat: Automated exploit attempts began targeting vulnerable sites globally within hours of public disclosure on July 17th.

Actions We Have Already Taken

To protect client websites and maintain environment integrity, our team took immediate action upon the official patch release on July 17th:

  1. WordPress Care & Maintenance Subscribers: All client websites subscribed to our WordPress Care & Maintenance plan were audited and updated immediately.
  2. Installatron Automatic Updates: Sites configured with automatic core updates enabled in Installatron were automatically patched to safe versions that night.
  3. Web Application Firewall Protection: We deployed server-level firewall rules across our platform to intercept and block known exploit attempts.

What You Need to Do

While our active firewall rules block incoming attack attempts, updating your WordPress software to a patched release is the only permanent fix.

  • If your WordPress site is already updated to version 6.8.6, 6.9.5 or 7.0.2 (or higher):
    You are fully protected! No further action is required.
  • If your site is running a vulnerable version of the 6.8, 6.9 or 7.0 branch:
    Please update your site immediately. You can do this easily in one of two ways:
    • Option 1: Log in to your cPanel control panel, open Installatron, locate your WordPress site and click the update button.
    • Option 2: Log in directly to your WordPress Admin Dashboard (/wp-admin), navigate to Dashboard > Updates, and click Update Now.

If you have any questions or need assistance verifying whether your site is running a safe version, please open a support ticket with our technical support team—we are here to help!

Important Security Update: How to Protect Your WordPress Website

June 12, 2026

Over the past few months, the landscape of website security has experienced a sudden and dramatic paradigm shift. We want to share what we have been facing behind the scenes, how our industry is evolving and—most importantly—the practical steps you can take to keep your website safe.

The New Reality: AI-Accelerated Exploits

Historically, website security operated at a predictable pace. A critical vulnerability might surface once or twice a year, giving website owners and system administrators plenty of time to review change logs, assess threats and schedule a convenient patch window.

That era is officially over.

As detailed in our recent blog post, Securing Your Websites Against 0-Day Threats, we have faced a rapid, continuous barrage of critical zero-day threats occurring weekly, and at times even daily.

This shift is being driven by the maturation of advanced AI tools. Both security researchers and malicious actors are now using AI to audit source code at lightning speed.

  • The Good: Defenders can find deep, systemic flaws that went unnoticed by human eyes for years.
  • The Bad: The moment a patch or a public disclosure is released, automated tools can instantly reverse-engineer it to find the exploit.

As a result, vulnerabilities are being actively exploited in the wild mere hours after public disclosure. The traditional concept of “scheduling a patch window next week” is no longer viable. Maintaining security now requires constant, immediate attention.

Looking Ahead: The Next 3 to 12 Months

Our security vendors have declared that we are in the middle of a permanent industry shift. Experts project that this rapid pace of vulnerability discoveries will persist aggressively for the next 3 to 6 months, with an elevated threat environment remaining for the next 1 to 2 years as AI tools continue to improve.

Continuous, automated updating is the new standard for web safety.

Why Keeping Your WordPress Software Current Matters

Because the vast majority of our customers run on WordPress, it’s vital to understand how this impacts your daily operations.

The #1 cause of website compromises is failing to keep website software up to date.

WordPress plugins are highly targeted by attackers using AI tools to find hidden flaws. A prime example occurred recently with UpdraftPlus, a massive backup plugin with millions of installations. A critical vulnerability was discovered that allowed for full website compromise if left unpatched.

When your site runs outdated plugins, it is only a matter of time before automated scripts locate the vulnerability.

Server-Level Defence vs. Core Patching

To help counter these threats, all Varial Hosting plans include an AI-driven, proactive firewall designed to help intercept malicious traffic and mitigate many zero-day exploits in real time. Powered by our Imunify360 security suite, its malware protection also adds an extra layer of defence by working to automatically detect and quarantine known malicious code before it can cause damage to your site.

While these server-level features are must-have modern security tools, patching vulnerable application code directly remains the single best defence against exploits.

3 Ways to Keep Your WordPress Site Up to Date

To protect your business and reputation, you need an update strategy that fits your workflow. We provide three distinct paths to handle this on our platform:

1. Manual Updates via WP-Admin (Self-Managed)

You can log directly into your WordPress wp-admin dashboard regularly to manually update your WordPress core, plugins and themes. Because of the accelerated timeline of modern attacks, you should frequently check for and apply updates to ensure you aren’t left exposed to active exploits.

2. Automated or Manual Updates via Installatron in cPanel (Recommended)

You can utilize the Installatron tool located inside your cPanel control panel. Installatron offers a massive safety net: it automatically takes a complete backup of your website before performing any update, allowing you to easily roll back with a single click if there are any issues.

  • WordPress Core (Our Default): By default, Installatron is set to automatically update your core WordPress software. Core releases are heavily tested and rarely introduce bugs.
  • Plugins and Themes (Optional): Automatic updates for plugins and themes are optional and turned off by default. Because anyone can write a plugin, they may not be as thoroughly tested and could occasionally introduce conflicts or functionality changes that could negatively impact your website. If you choose to enable automatic updates for plugins and themes, we highly recommend reviewing your website after receiving an update notification to ensure everything is working properly.

3. WordPress Care & Maintenance Plan (Fully Managed)

For businesses and organizations that want total peace of mind without the hassle, our fully managed WordPress Care & Maintenance Plan is available.

With this plan, our team handles the entire process for you. We don’t just blindly update your site; we deploy and test all updates in a private staging environment first to ensure there are no conflicts or layout issues before safely pushing them live. This allows you to focus 100% on running your business while we ensure your website remains locked down.

The security landscape has changed permanently, but by shifting to a proactive, continuous update mindset, you can keep your data and websites secure.

If you would like to enrol in our Care & Maintenance plan, or need help configuring Installatron for automated backups and updates, please contact us or open a ticket with our support team.

WordPress 6.3 to Drop Support for PHP 5

July 6, 2023

WordPress have announced that they will be dropping support for PHP 5 in their upcoming 6.3 version which is expected to be released in August.

Currently, WordPress 6.2 requires PHP 5.6 at a minimum. With the release of 6.3, WordPress will require PHP 7.0 at a minimum, with PHP 7.4 or higher being recommended for use.

Sites that remain on PHP 5.6 will be unable to upgrade to newer versions but will continue to receive security updates for WordPress’ 6.2 branch.

If you are still using PHP 5 and would like to continue upgrading to new versions of WordPress you must switch to PHP 7 or higher.

Varial Hosting customers can change their PHP version at any time by logging into your cPanel control panel and clicking on the “Select PHP Version” icon.

It is recommended to upgrade WordPress and your themes and plugins before switching your PHP version to ensure that all of your website code is made compatible with the newer versions of PHP.

If you require assistance changing your PHP version, feel free to contact our support department.

WordPress 6.0 is Now Available

May 26, 2022

WordPress 6.0 has just been released and offers many refinements and improvements to the full site editing experience introduced in WordPress 5.9. You can read about all the new features at: https://wordpress.org/news/2022/05/arturo/

Varial Hosting customers who have automatic upgrades enabled through Installatron will be automatically upgraded to this new version. All other users may manually upgrade using Installatron or from their WordPress administrative areas.

WordPress 5.9 is Now Available

January 26, 2022

WordPress 5.9 has just been released and introduces full site editing and the first default block theme, Twenty Twenty-Two.

Using full site editing and compatible block themes, you can now easily customize the look and feel of your entire website using a visual drag-and-drop interface right within WordPress.

Varial Hosting customers who have automatic upgrades enabled through Installatron will be automatically upgraded to this new version. All other users may manually upgrade using Installatron or from their WordPress administrative areas.