{"id":10160,"date":"2026-07-20T11:52:57","date_gmt":"2026-07-20T11:52:57","guid":{"rendered":"https:\/\/rettenmund.com\/2026\/07\/critical-wordpress-vulnerability-is-being-actively-exploited-heres-what-you-should-do-now\/"},"modified":"2026-07-22T12:45:04","modified_gmt":"2026-07-22T12:45:04","slug":"critical-wordpress-vulnerability-is-being-actively-exploited-heres-what-you-should-do-now","status":"publish","type":"post","link":"https:\/\/rettenmund.com\/en\/2026\/07\/critical-wordpress-vulnerability-is-being-actively-exploited-heres-what-you-should-do-now\/","title":{"rendered":"Critical WordPress Security Vulnerability &#8211; Millions of WordPress Websites Are Under Active Attack \u2013 What You Should Do Now"},"content":{"rendered":"<p>A serious security vulnerability in WordPress has been publicly known since July 17, 2026. It is called \u201cwp2shell\u201d and is now being actively exploited in attacks. It\u2019s not a single plugin that\u2019s affected, but the core of WordPress itself\u2014meaning virtually every standard installation. Since WordPress powers an estimated 500 million websites worldwide, the problem affects a huge portion of the internet.   <\/p>\n<p>First, the good news: There\u2019s already an update available that patches the vulnerability. Anyone who runs a WordPress website should take action now\u2014preferably today. <\/p>\n<h2>What&#8217;s behind &#8220;wp2shell&#8221;?<\/h2>\n<p>Simply put: Attackers can use wp2shell to execute third-party code on your server\u2014without having to log in first. No user account, no password, and no vulnerable plugin are required. All it takes is for your WordPress site to be publicly accessible on the Internet.  <\/p>\n<p>Technically, this is a combination of two interrelated vulnerabilities. Each on its own would be less serious\u2014but together, they allow an attacker to take over a website. To do this, attackers send a specially crafted request to the so-called REST interface, which WordPress normally uses to exchange data in the background. In one instance, a security check is bypassed. Experts have assigned the vulnerability the identifier CVE-2026-63030.    <\/p>\n<p>The security researchers involved are deliberately withholding the exact details of how the vulnerability can be exploited so that website operators have time to patch it. Nevertheless, a working exploit was already circulating online just a few hours after the disclosure. <\/p>\n<h2>Why this is such a serious matter<\/h2>\n<p>The German Federal Office for Information Security (BSI) has issued a warning and classified the vulnerability as Level 3 out of 4 (Orange). Several security firms and the BSI confirm that the vulnerability is already being exploited in the wild. <\/p>\n<p>The speed at which this happened is particularly concerning: Only a few hours passed between the disclosure of the vulnerability, the release of the first public exploit code, and the first actual attacks. So the real problem isn\u2019t the lack of a patch\u2014one is available. What\u2019s dangerous is the window of time in between, during which many sites haven\u2019t been updated yet. It\u2019s precisely during this window that attackers strike.   <\/p>\n<h2>Am I affected?<\/h2>\n<p>The following WordPress versions are affected:<\/p>\n<ul>\n<li>6.8.0 through 6.8.5<\/li>\n<li>6.9.0 through 6.9.4<\/li>\n<li>7.0.0 through 7.0.1<\/li>\n<li>as well as the beta version of 7.1<\/li>\n<\/ul>\n<p>You&#8217;re sure to be using one of these versions:<\/p>\n<ul>\n<li>7.0.2 (current branch)<\/li>\n<li>6.9.5<\/li>\n<li>6.8.6<\/li>\n<\/ul>\n<p>You can find your current version in the WordPress admin area at the bottom right of the dashboard or under &#8220;Tools \u2192 Site Health.&#8221;<\/p>\n<h2>What You Should Do Specifically Right Now<\/h2>\n<ol>\n<li><strong>Check for updates and install them.<\/strong>  Due to the severity of the issue, WordPress has enabled automatic forced updates. Many sites have already been secured as a result. However, don\u2019t rely on this blindly: Check for yourself whether your installation is actually running version 7.0.2, 6.9.5, or 6.8.6. In some cases, the automatic update did not work properly.   <\/li>\n<li><strong>Use the Quick Check.<\/strong>  A free online scanner is available at wp2shell.com. Simply enter your URL, and even without any technical knowledge, you can find out if your site is still vulnerable. <\/li>\n<li><strong>Enable additional protection via Cloudflare.<\/strong>  If your traffic goes through Cloudflare, the service has published appropriate firewall rules\u2014for both free and paid plans. This provides an additional layer of protection, but it does not replace the update. <\/li>\n<li><strong>Check for signs of an attack.<\/strong>  If your site hasn&#8217;t been updated for a long time, you should check to see if any WordPress files have been modified unexpectedly or if there are any suspicious new users, files, or posts.<\/li>\n<\/ol>\n<h2>In short<\/h2>\n<p>wp2shell is one of the more serious WordPress vulnerabilities to emerge recently: it\u2019s embedded in the core, can be exploited without login, and is already actively circulating. If you update to one of the secure versions as soon as possible and verify that the update was successful, you\u2019ll be on the safe side. If you\u2019re unsure whether your site has been updated properly\u2014or whether it\u2019s already been compromised\u2014it\u2019s better to check once too often than not enough.  <\/p>\n","protected":false},"excerpt":{"rendered":"A serious security vulnerability in WordPress has been publicly known since July 17, 2026. It is called \u201cwp2shell\u201d and is now being actively exploited in attacks. It does not affect a single plugin, but rather the core of WordPress itself\u2014meaning virtually every standard installation.  ","protected":false},"author":9,"featured_media":10162,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1159,1429],"tags":[1521,1171,1522,1520],"class_list":["post-10160","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-websites-en","category-wordpress","tag-cyberattack","tag-wordpress-en","tag-wordpress-isnt-working","tag-wp2shell"],"acf":[],"_links":{"self":[{"href":"https:\/\/rettenmund.com\/en\/wp-json\/wp\/v2\/posts\/10160","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rettenmund.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rettenmund.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rettenmund.com\/en\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/rettenmund.com\/en\/wp-json\/wp\/v2\/comments?post=10160"}],"version-history":[{"count":3,"href":"https:\/\/rettenmund.com\/en\/wp-json\/wp\/v2\/posts\/10160\/revisions"}],"predecessor-version":[{"id":10175,"href":"https:\/\/rettenmund.com\/en\/wp-json\/wp\/v2\/posts\/10160\/revisions\/10175"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/rettenmund.com\/en\/wp-json\/wp\/v2\/media\/10162"}],"wp:attachment":[{"href":"https:\/\/rettenmund.com\/en\/wp-json\/wp\/v2\/media?parent=10160"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rettenmund.com\/en\/wp-json\/wp\/v2\/categories?post=10160"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rettenmund.com\/en\/wp-json\/wp\/v2\/tags?post=10160"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}