Skip to content
Devonport, Tasmania · web design for aspiring businesses across Australia
★★★★★ Rated 4.8 on Google Request a chat

Security notice

WP2Shell: critical WordPress core vulnerability chain

Critical 3 August 2026 · WordPress Core security release, CISA KEV

WP2Shell chains two flaws in WordPress core to give an anonymous attacker full remote code execution on a stock install, with no plugins, no configuration quirks and no login required. It is being exploited in the wild. If you run WordPress, confirm you are on 6.9.5, 7.0.2 or 6.8.6 or later today, and check your site for the signs of compromise listed below.

What's happening

WP2Shell is a pre-authentication remote code execution chain in WordPress core itself, not in a plugin or a theme. It was found by researchers at Searchlight Cyber and disclosed on 17 July 2026. It combines two separate flaws:

Chained together, an attacker anywhere on the internet gets code execution on a default WordPress installation. There are no preconditions. No plugins are required, no unusual configuration, no user interaction, and no existing account. In observed attacks the payload is used to create an administrator account, log in, and install a malicious plugin, which then drops a persistent webshell on the server.

Both CVEs were added to CISA's Known Exploited Vulnerabilities catalog on 21 July 2026, which confirms active exploitation. Multiple working proof-of-concept exploits were public within days of disclosure, so the barrier to running this attack is now very low.

You can read the official WordPress release announcement for the vendor's own account of the fix.

Affected and fixed versions

WordPress enabled forced automatic updates for affected sites, which has patched a large share of installs without anyone lifting a finger. Do not treat that as a guarantee. Forced updates do not land on sites with auto-updates disabled, sites where file permissions prevent core from writing to itself, sites whose host defers or manages updates on its own schedule, or sites where core files have been modified. Verify the version yourself rather than assuming it was handled.

What to do if you run a WordPress site

Signs of compromise to look for

One important detail about this attack: it is largely log blind. The malicious instructions travel inside the body of a batch POST request, so a normal access log shows an unremarkable POST to a valid endpoint and nothing more. Database evidence is more reliable than server logs here.

If any of these turn up, preserve the evidence before you start cleaning. Take a copy of the database and the web root first, so the entry point and the timeline can still be traced. A cleanup done in a hurry usually destroys the only record of what actually happened, and often misses a second backdoor.

How we help our clients

This one undercuts the usual advice. The standard guidance for WordPress security is to keep your plugins lean and your themes trustworthy. That advice is sound, and it would not have helped here. WP2Shell needed no plugins at all. A perfectly maintained, stock install was fully exploitable by an anonymous attacker, because the vulnerability was in the platform.

That is the argument we keep making. Most small business websites do not need a public REST API, a database and an admin login exposed to the internet. Jigsaw, our alternative, has none of them, so this entire class of vulnerability simply does not apply.

For clients whose site genuinely needs a CMS, our WordPress management plan runs on tooling rather than on someone remembering to click update: versions tracked against published vulnerability data so security releases are applied on our schedule, multi-factor authentication on administrator logins, brute force protection, alerting on new or newly escalated admin accounts, a web application firewall, malware and file integrity scanning, and hourly off-server backups. The account alerting earns its keep here, because creating a rogue administrator is the first thing a WP2Shell payload does.

If you are not sure which version your site is running, or you would like us to check it for the indicators above, request a chat.


Corey Crowden
Corey Crowden Creative and Technical Lead (And director of Tas Web Co)
Back Return to all notices