The WordPress “wp2shell” Vulnerability: What Happened and What to Do Now
In mid-July 2026, a critical security flaw in WordPress core, the software that powers a large share of the world’s business websites, went from a routine patch to a full-blown, internet-wide attack campaign in a matter of days. If your website runs on WordPress, here is what happened, why it matters, and exactly what to do about it.
At DDSystems, we identified the attack activity early and moved quickly to protect every website and server we manage. We are sharing the details here because the threat is real, it is ongoing, and many business owners have no easy way to know whether their own site is exposed.
The bottom line
WordPress 7.0.2 fixes a critical flaw that lets attackers take over unpatched sites without a password. Public exploit code is circulating and the attacks are automated and ongoing. Every WordPress site should be updated to the patched version immediately, and any site that may have been exposed before patching should also be checked for hidden malicious code.
What happened
WordPress issued an emergency security release, version 7.0.2, to fix two vulnerabilities in its core software. The most serious of the two, now widely known by the nickname “wp2shell” and tracked as CVE-2026-63030, is a critical flaw in the WordPress REST API. It allows an attacker to run their own code on a website and take it over completely, without ever logging in. The second issue, CVE-2026-60137, is a high-severity SQL injection flaw that was patched in the same release.
The problem affects more than one version of WordPress. WordPress 7.0 and 7.0.1 are vulnerable and are fixed by 7.0.2. Older supported branches were patched at the same time through versions 6.9.5 and 6.8.6. In short, any WordPress site that had not installed the security update was at risk.
Within days of the release, security researchers published working exploit code, and attackers began scanning and hitting vulnerable sites at massive scale.
Why “wp2shell” is so dangerous
Not every website vulnerability is created equal. A few characteristics make this one especially severe:
- No login required. The attacker does not need a username, a password, or any existing access. This is what security professionals call a pre-authentication vulnerability, and it is the most dangerous kind.
- Full remote takeover. A successful attack lets the intruder run their own code on your server, which means they can deface the site, plant hidden backdoors, steal data, or use your site to attack others.
- It targets a feature that is on by default. The flaw is in the WordPress REST API, which is enabled on essentially every WordPress site, so there is nothing unusual a site needs to have installed to be exposed.
- The attacks are automated. Bots are sweeping the internet looking for any unpatched site, so a small business website is just as likely to be hit as a large one.
What a compromised site can look like
Because the goal of many of these attacks is speed and scale, the results are often visible. Signs that a WordPress site may have been compromised include:
- A fake “maintenance” or “coming soon” page replacing the real site, sometimes with awkward or broken wording such as “Briefly unavailable for scheduled maintenance. Check back in a some hours.”
- The homepage or pages redirecting visitors to unfamiliar or suspicious websites.
- New pages, posts, or files that no one on your team created.
- Administrators suddenly unable to log in, or unfamiliar admin accounts appearing.
- The site running noticeably slowly, throwing errors, or being flagged by browsers or your hosting provider.
- Warnings that your domain or server has been placed on a spam or malware blocklist.
It is worth stressing that a site can be compromised without any obvious signs at all. Some attackers stay quiet on purpose, leaving a hidden backdoor so they can return later.
What we did for the sites we manage
As soon as we recognized the attack pattern, our team worked through every website and server under our management. For each one, we:
- Patched and updated. Updated WordPress core to the patched 7.0.2 release, along with plugins and themes, closing the flaw at its source.
- Scanned and cleaned. Inspected every site for malicious code and removed any threats found.
- Hardened. Blocked the specific attack paths at the server level, added firewall rules, and tightened file permissions.
- Verified. Confirmed each site is clean against known-good baselines, with backups in place.
Updating is essential, but on its own it may not be enough
Here is a detail that catches many site owners off guard. Installing the update closes the door that attackers used to get in, but it does not remove anything they may have already left behind. If a site was compromised in the window before it was patched, a hidden backdoor can remain in place even after the software shows the latest, fixed version number.
In other words, a site can report that it is fully up to date and still be harboring malicious code from an earlier break-in. That is why proper recovery means two things: patch to close the vulnerability, and then check the site for any signs of an existing compromise. Updating alone can create a false sense of safety.
What you should do right now
If you manage your own WordPress site, or you are simply not sure whether it has been handled, here are the steps that matter most:
- Check your WordPress version. In your dashboard, go to Dashboard and then Updates, or look at the bottom of the admin screen. Anything below the 7.0.2 security release is a concern.
- Update immediately. Install the latest WordPress core release, then update all plugins and themes. WordPress also pushed forced automatic updates for affected versions, but do not assume that reached your site. Confirm it.
- Look for signs of compromise. Review your site for the warning signs listed above, and check for admin accounts or content you do not recognize.
- Do not rely on the version number alone. If there is any chance your site was exposed before it was patched, have it checked for hidden malicious code, not just updated.
- Confirm who is responsible. If your website is hosted or maintained by another company, ask them directly whether your site has been patched and reviewed for this specific issue.
If DDSystems does not manage your site
If we already manage your website and hosting, your sites have been patched, cleaned, and hardened, and there is nothing you need to do. But if your site lives elsewhere, or you are not certain it has been handled, it may still be exposed to this exact flaw. A vulnerable WordPress site can be compromised within hours, and the longer it stays unpatched, the greater the risk.
We would be glad to review your site, confirm it is running the patched release, check it for any signs of compromise, and secure it. There is no obligation, and we are always happy to help a fellow business protect what it has built.
Final word
Update your WordPress site now, and if there is any chance it was exposed before patching, have it checked for backdoors rather than assuming the update fixed everything. Speed matters, but so does verifying the site is actually clean.
Not sure if your WordPress site is protected?
DDSystems helps organizations across Maryland, DC, and Delaware keep their websites patched, monitored, and secure. Let’s take a look at yours and make sure it is safe.
Request a Security Review