WordPress WP2Shell security alert
A newly disclosed WordPress Core security vulnerability, known as WP2Shell, has prompted WordPress to release emergency security updates across multiple supported versions.
Unlike many WordPress vulnerabilities, this issue is found in WordPress Core itself, rather than in a plugin or theme. This means websites running an affected version of WordPress could be at risk even if they have very few plugins installed and no compromised user accounts.
To ensure your website is protected, update WordPress Core to at least one of the following versions:
- WordPress 7.0.2
- WordPress 6.9.5
- WordPress 6.8.6
It’s also worth noting that the free version of Wordfence is not expected to include protection for this vulnerability until 16 August 2026, making prompt WordPress Core updates especially important.
While updating plugins, themes and PHP will not address this specific vulnerability, keeping them current remains an important part of maintaining a secure, reliable and well-performing website.
For a detailed technical explanation of WP2Shell, see Wordfence’s article:
https://www.wordfence.com/blog/2026/07/wp2shell-aftermath-the-first-critical-unauthenticated-wordpress-core-rce-in-nearly-a-decade/
If you’d prefer someone else to handle WordPress updates, security monitoring and ongoing maintenance, Creative Passion is always happy to help. Our existing Website Maintenance clients have already been updated and are protected against this vulnerability.