On July 17, 2026, the WordPress Security Team released critical updates addressing two vulnerabilities that can lead to unauthenticated remote code execution, collectively known as wp2shell. This affects WordPress versions 6.8.x, 6.9.x, and 7.0.x, and site owners are urged to update immediately to avoid potential exploitation.
Key Takeaways
- Update to WordPress versions 6.8.6, 6.9.5, or 7.0.2 immediately.
- The wp2shell vulnerabilities allow attackers to gain full control without authentication.
- Exploitation activity started within hours of the patch release; act fast to secure your site.
What is wp2shell?
The wp2shell vulnerabilities involve two issues: CVE-2026-60137, an unauthenticated SQL injection, and CVE-2026-63030, a REST API batch request route-confusion issue. Together, they allow attackers to execute code on vulnerable WordPress installations without needing authentication, posing a significant risk to site security.
Which WordPress Versions Are Affected?
WordPress versions 6.8.x, 6.9.x, and 7.0.x are affected. Specifically, versions 6.9.x and 7.0.x are vulnerable to both issues, while 6.8.x is only affected by the SQL injection vulnerability. It’s critical for site owners running these versions to confirm they have updated to 6.8.6, 6.9.5, or 7.0.2.
What Should You Do Now?
Site owners should take the following steps immediately: confirm your WordPress version, update to the latest patched version, verify that the update completed successfully, and review administrator accounts and recent changes. Given the rapid exploitation attempts observed, acting quickly is essential to secure your site.
Frequently Asked Questions
What versions of WordPress are affected by the wp2shell vulnerabilities?
WordPress versions 6.8.x, 6.9.x, and 7.0.x are affected; update to 6.8.6, 6.9.5, or 7.0.2.
What are the CVE identifiers for the wp2shell vulnerabilities?
The vulnerabilities are tracked as CVE-2026-60137 and CVE-2026-63030.
When were the security updates released?
The updates were released on July 17, 2026.
What should site owners do to secure their installations?
Site owners should confirm their WordPress version, update to the latest patched version, and verify that the update completed successfully.
Why is it urgent to update WordPress now?
Exploitation activity started within hours of the patch release, making immediate action essential to prevent site compromise.