Critical WordPress Security Vulnerability – Millions of WordPress Websites Are Under Active Attack – What You Should Do Now

In short:

A serious security vulnerability in WordPress has been publicly known since July 17, 2026. It is called “wp2shell” and is now being actively exploited in attacks. It does not affect a single plugin, but rather the core of WordPress itself—meaning virtually every standard installation.

A serious security vulnerability in WordPress has been publicly known since July 17, 2026. It is called “wp2shell” and is now being actively exploited in attacks. It’s not a single plugin that’s affected, but the core of WordPress itself—meaning virtually every standard installation. Since WordPress powers an estimated 500 million websites worldwide, the problem affects a huge portion of the internet.

First, the good news: There’s already an update available that patches the vulnerability. Anyone who runs a WordPress website should take action now—preferably today.

What’s behind “wp2shell”?

Simply put: Attackers can use wp2shell to execute third-party code on your server—without having to log in first. No user account, no password, and no vulnerable plugin are required. All it takes is for your WordPress site to be publicly accessible on the Internet.

Technically, this is a combination of two interrelated vulnerabilities. Each on its own would be less serious—but together, they allow an attacker to take over a website. To do this, attackers send a specially crafted request to the so-called REST interface, which WordPress normally uses to exchange data in the background. In one instance, a security check is bypassed. Experts have assigned the vulnerability the identifier CVE-2026-63030.

The security researchers involved are deliberately withholding the exact details of how the vulnerability can be exploited so that website operators have time to patch it. Nevertheless, a working exploit was already circulating online just a few hours after the disclosure.

Why this is such a serious matter

The German Federal Office for Information Security (BSI) has issued a warning and classified the vulnerability as Level 3 out of 4 (Orange). Several security firms and the BSI confirm that the vulnerability is already being exploited in the wild.

The speed at which this happened is particularly concerning: Only a few hours passed between the disclosure of the vulnerability, the release of the first public exploit code, and the first actual attacks. So the real problem isn’t the lack of a patch—one is available. What’s dangerous is the window of time in between, during which many sites haven’t been updated yet. It’s precisely during this window that attackers strike.

Am I affected?

The following WordPress versions are affected:

  • 6.8.0 through 6.8.5
  • 6.9.0 through 6.9.4
  • 7.0.0 through 7.0.1
  • as well as the beta version of 7.1

You’re sure to be using one of these versions:

  • 7.0.2 (current branch)
  • 6.9.5
  • 6.8.6

You can find your current version in the WordPress admin area at the bottom right of the dashboard or under “Tools → Site Health.”

What You Should Do Specifically Right Now

  1. Check for updates and install them. Due to the severity of the issue, WordPress has enabled automatic forced updates. Many sites have already been secured as a result. However, don’t rely on this blindly: Check for yourself whether your installation is actually running version 7.0.2, 6.9.5, or 6.8.6. In some cases, the automatic update did not work properly.
  2. Use the Quick Check. A free online scanner is available at wp2shell.com. Simply enter your URL, and even without any technical knowledge, you can find out if your site is still vulnerable.
  3. Enable additional protection via Cloudflare. If your traffic goes through Cloudflare, the service has published appropriate firewall rules—for both free and paid plans. This provides an additional layer of protection, but it does not replace the update.
  4. Check for signs of an attack. If your site hasn’t been updated for a long time, you should check to see if any WordPress files have been modified unexpectedly or if there are any suspicious new users, files, or posts.

In short

wp2shell is one of the more serious WordPress vulnerabilities to emerge recently: it’s embedded in the core, can be exploited without login, and is already actively circulating. If you update to one of the secure versions as soon as possible and verify that the update was successful, you’ll be on the safe side. If you’re unsure whether your site has been updated properly—or whether it’s already been compromised—it’s better to check once too often than not enough.

Wenn auch Sie mit einer Herausforderung konfrontiert sind und Unterstützung oder Beratung benötigen, dann kontaktieren Sie uns gerne.

Für allgemeine Anfragen / Offertanfragen / Projektfragen:

E-Mail: solutions@rettenmund.com

Zur Blog-Übersicht

More interesting new articles

WE WORK FOR, AMONG OTHERS ...

Stiftung für Konsumentenschutz

swiss alpine herbs - SWISSALPINEHERBS

Schweizerische Eidgenossenschaft

BETAX Genossenschaft BERN

männer.ch - Dachverband Schweizer Männer- & Väterorganisationen

UBS Bank - Y

medbase Gruppe

REKA Genossenschaft

Kyburz Saphire, Safnern - Optische Komponenten Saphir, Keramik

Edition Königstuhl

Gemeinde Urtenen-Schönbühl

LKBV - Luzerner Kantonal-Blasmusikverband

stadtwerke kongress aarau

Casafair - Eigentum mit Verantwortung

Green Golfreisen

Swisspower AG

Gemeinde Moosseedorf

Einwohnergemeinde Lengnau

reCIRCLE AG - Die Mehrwegsystem-Lösung

HESAV - Haute Ecole de Santé Vaud