Chain of Critical Vulnerabilities in WordPress, wp2shell

Posted date 28/07/2026

In mid-July 2026, a chain of critical vulnerabilities affecting the WordPress core was made public, subsequently dubbed ‘wp2shell’. The incident stemmed from two flaws in WordPress Core which, when combined, allowed a remote attacker to execute code without needing to authenticate or exploit additional plugins or themes. The WordPress team coordinated the disclosure of the incident with the researchers who had responsibly reported it via its bug bounty programme, whilst simultaneously releasing security updates to fix the issue. The release of these updates marked the start of the official response to a threat affecting vulnerable installations of the content management system.

Following the release of the patches, several cybersecurity firms confirmed that the chain of vulnerabilities was being actively exploited against sites that had not yet been updated. The attacks observed involved the installation of webshells, the creation of users with administrative privileges, and the deployment of malicious plugins to maintain persistence on compromised systems. The affected versions were specific branches of WordPress 6.8, 6.9 and 7.0, whilst the project released the corrective versions 6.8.6, 6.9.5 and 7.0.2. As an additional measure, the WordPress team enabled forced automatic updates for compatible installations and advised administrators to update their sites immediately, as well as to check whether they had been compromised before simply applying the patch.

Currently, the incident is classified as a fixed vulnerability, with security updates available for all affected branches and documented exploitation campaigns targeting systems that remained unpatched. The WordPress project maintains its official recommendation to install the patched versions via the automatic or manual update mechanism, whilst various cybersecurity organisations and bodies continue to warn of exploitation attempts targeting vulnerable installations. To date, the official information released by WordPress has focused on the availability of the fixes and the need to keep sites up to date, without reporting any subsequent changes regarding the scope of the incident or announcing any further measures relating to this chain of vulnerabilities.