{"id":43263,"date":"2026-07-23T17:10:20","date_gmt":"2026-07-23T15:10:20","guid":{"rendered":"https:\/\/csw.agency\/?p=43263"},"modified":"2026-07-23T18:21:31","modified_gmt":"2026-07-23T16:21:31","slug":"wp2shell-wordpress","status":"publish","type":"post","link":"https:\/\/csw.agency\/en\/wp2shell-wordpress\/","title":{"rendered":"wp2shell forces WordPress websites to update"},"content":{"rendered":"<p>WordPress is one of the most widely used content management systems worldwide, and consequently, the attack surface is large when a critical vulnerability appears in the core of the system. This is exactly what happened with wp2shell, a combination of two vulnerabilities that together create a <strong>unauthorized code execution<\/strong> enable. Security researchers are already confirming active attacks on the internet, so time is of the essence.<\/p>\n<h2>What's behind wp2shell<\/h2>\n<p>wp2shell refers to the combination of two vulnerabilities in the WordPress core that are much more dangerous together than each one is on its own. CVE-2026-63030 is in the <strong>REST API<\/strong> and causes confusion between different batch routes, allowing multiple requests to be evaluated differently in a single call than actually intended by the system, <a href=\"https:\/\/thehackernews.com\/2026\/07\/new-wp2shell-wordpress-core-flaw-lets.html\" target=\"_blank\" rel=\"noopener\">The Hacker News<\/a> describes the mechanism in detail in its own analysis. CVE-2026-60137 is a <strong>SQL Injection<\/strong> in the parameter author__not_in of the WP_Query class, which is used in the background with the <a href=\"https:\/\/csw.agency\/en\/glossar\/mysql\/\">MySQL<\/a>-database communicates and is supposed to actually filter out only authors there. Combined, both loopholes allow an anonymous attacker <em>Remote Code Execution<\/em>, So, executing your own code on a foreign server, regardless of whether additional security plugins are installed.<\/p>\n<p>Installations from versions 6.8.0 to 6.8.5 are affected by the SQL injection alone, and versions 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1 are affected by the complete, much more dangerous chain of both vulnerabilities. Those running versions older than 6.8 are not affected, which, given outdated installations and their own risks, is rarely of any real comfort. The two vulnerabilities were discovered and reported independently: the REST API vulnerability by Assetnote and Searchlight Cyber, and the SQL injection by the research team TF1T, dtro, and haongo. The WordPress core team responded with a <strong>Emergency Update<\/strong> for all three affected version branches. The details about the official patch have <a href=\"https:\/\/wordpress.org\/news\/2026\/07\/wordpress-7-0-2-release\/\" target=\"_blank\" rel=\"noopener\">WordPress<\/a> published in a separate post, including a technical description of both vulnerabilities.<\/p>\n<h2>Why the attack is so dangerous<\/h2>\n<p>The combination of both loopholes works without registration and without a single installed <a href=\"https:\/\/csw.agency\/en\/glossar\/plugin\/\">Plugin<\/a>, A standard WordPress is already enough of a target. This is precisely what distinguishes wp2shell from most security vulnerabilities of recent years, which usually found their way into the system via vulnerable extensions or themes and could therefore be more easily contained. <a href=\"https:\/\/expertinsights.com\/news\/wordpress-force-pushes-fix-for-wp2shell\" target=\"_blank\" rel=\"noopener\">ExpertInsights<\/a> calls the vulnerability the first critical, unauthenticated remote code execution in the WordPress core in nearly a decade. Those who underestimate the scope risk full compromise of their server, including the database, customer data, and in the worst case, also linked systems such as newsletter tools or payment providers.<\/p>\n<p>As early as July 17, 2026, the security service provider Wordfence registered the first test requests to the REST API, followed by the first real injection attempt a few minutes later. Shortly thereafter, a public repository appeared on GitHub <em>Proof of Concept<\/em> which made the complete attack chain understandable step by step, thereby also making it easier for less experienced attackers to get started. The Federal Office for Information Security subsequently classified the situation as <strong>Alert Level Orange<\/strong> one, how <a href=\"https:\/\/www.heise.de\/en\/news\/WordPress-vulnerability-wp2shell-is-being-attacked-11372307.html\" target=\"_blank\" rel=\"noopener\">heise<\/a> in its ongoing reporting. Also <a href=\"https:\/\/www.securityweek.com\/wp2shell-wordpress-vulnerabilities-exploited-in-the-wild\/\" target=\"_blank\" rel=\"noopener\">SecurityWeek<\/a> confirmed active attacks on the web and classified the campaign as one of the more serious WordPress incidents of the current year.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-43268 aligncenter\" src=\"https:\/\/csw.agency\/wp-content\/uploads\/5E575726-86A3-427C-8D3B-E582A9095287.jpeg\" alt=\"\" width=\"1131\" height=\"637\" srcset=\"https:\/\/csw.agency\/wp-content\/uploads\/5E575726-86A3-427C-8D3B-E582A9095287.jpeg 1672w, https:\/\/csw.agency\/wp-content\/uploads\/5E575726-86A3-427C-8D3B-E582A9095287-300x169.jpeg 300w, https:\/\/csw.agency\/wp-content\/uploads\/5E575726-86A3-427C-8D3B-E582A9095287-1024x576.jpeg 1024w, https:\/\/csw.agency\/wp-content\/uploads\/5E575726-86A3-427C-8D3B-E582A9095287-768x432.jpeg 768w, https:\/\/csw.agency\/wp-content\/uploads\/5E575726-86A3-427C-8D3B-E582A9095287-1536x864.jpeg 1536w, https:\/\/csw.agency\/wp-content\/uploads\/5E575726-86A3-427C-8D3B-E582A9095287-18x10.jpeg 18w\" sizes=\"auto, (max-width: 1131px) 100vw, 1131px\" \/><\/p>\n<h2>What operators must do now<\/h2>\n<p>The most important step is simple, even though it's often postponed in daily business. Check which WordPress version your site is currently running on and update immediately to 6.8.6, 6.9.5, or 7.0.2, depending on which version branch you are using. Because the severity of the vulnerability allows no waiting time, the core team has enforced automatic background updates for affected versions, so many sites are already running on a patched version, provided the host has not disabled this function for their own reasons. Nevertheless, check the version number yourself in the backend, because especially with managed hosting packages and specially configured servers, their own update rules sometimes apply.<\/p>\n<ul>\n<li>Check the WordPress version in the dashboard under \u201eUpdates\u201c and manually update to 6.8.6, 6.9.5, or 7.0.2 if necessary, even for multiple installations.<\/li>\n<li>Review server and access logs from the past few days for unusual requests to the REST API, especially around July 17th.<\/li>\n<li>Create a fresh database backup before making major changes so you can cleanly revert in case of emergencies.<\/li>\n<li>Enable automatic updates in hosting so that future emergency patches are applied without delay.<\/li>\n<li>In case of suspected compromise, consistently reset passwords, salts, and API keys, and check user accounts.<\/li>\n<\/ul>\n<h2>WordPress maintenance as an ongoing task<\/h2>\n<p>wp2shell shows how quickly a solid website can become an open barn door if updates are neglected or responsibilities are unclear between the agency, host, and client. The WordPress core in particular was previously considered exemplary in its maintenance, making a vulnerability of this magnitude all the more deserving of attention. Anyone who wants their <a href=\"https:\/\/csw.agency\/en\/glossar\/cms-content-management-system\/\">CMS (Content Management System)<\/a> If maintenance is not performed regularly, you eventually rely on luck, and luck is not a concept of security, as is well known. You may already know deadlines of this kind from <a href=\"https:\/\/csw.agency\/en\/the-accessibility-act-bfsg\/\">Accessibility Strengthening Act<\/a>, every week counted there too, and just like back then, our <a href=\"https:\/\/csw.agency\/en\/services\/webengineering\/\">WordPress Agency D\u00fcsseldorf<\/a> also when it comes to the technical security and ongoing maintenance of your website.<\/p>\n<ul>\n<li>Anchor regular updates for WordPress, themes, and plugins firmly in your editorial calendar, rather than leaving them to chance.<\/li>\n<li>Implement a web application firewall and login protection to intercept attack attempts early<\/li>\n<li>Set up monitoring and uptime alerts so that anomalies are noticed immediately, not weeks later.<\/li>\n<li>Use a staging environment to thoroughly test updates before going live, instead of experimenting live on your own website.<\/li>\n<\/ul>\n<h2>FAQs about wp2shell<\/h2>\n<h3>What is wp2shell?<\/h3>\n<p>wp2shell is the name for a combination of two core WordPress vulnerabilities, CVE-2026-63030 and CVE-2026-60137. Together, they allow an unauthenticated attacker to execute arbitrary code on a remote server, without needing a valid account, plugin, or user interaction. The name wp2shell alludes to the fact that the end of the attack chain effectively leads to server takeover.<\/p>\n<h3>Which WordPress versions are affected?<\/h3>\n<p>The SQL injection affects versions 6.8.0 to 6.8.5, 6.9.0 to 6.9.4, and 7.0.0 to 7.0.1. The complete attack chain with code execution affects versions 6.9.0 and later up to and including 7.0.1. Versions older than 6.8 are not affected by wp2shell.<\/p>\n<h3>Do I have to update immediately?<\/h3>\n<p>Yes. As public exploit code is already circulating and active attacks have been confirmed, you should update immediately to 6.8.6, 6.9.5, or 7.0.2 and not wait for the next regular maintenance window.<\/p>\n<h3>Is the automatic update sufficient?<\/h3>\n<p>Yes, in most cases, because the core team has enabled forced background updates due to the severity of the gap. Nevertheless, manually check the version number in the dashboard in case automatic updates have been disabled for you or your host uses its own update rules.<\/p>\n<h3>How do I recognize a successful attack?<\/h3>\n<p>Watch out for unknown administrator accounts, modified files in the core directory, and unusual entries in the server logs around July 17, 2026. If in doubt, a look at your host's logs or a quick security audit by an experienced service provider can help, especially if you feel technically insecure.<\/p>","protected":false},"excerpt":{"rendered":"<p>A newly discovered vulnerability chain called wp2shell allows attackers to completely take over unpatched WordPress installations without any login or plugin. The WordPress core team responded within hours and is already providing a security update. You should still check yourself to see if your site is affected before someone else takes an interest.<\/p>","protected":false},"author":10,"featured_media":43265,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_lmt_disableupdate":"no","_lmt_disable":"","footnotes":"","_links_to":"","_links_to_target":""},"categories":[22,8],"tags":[],"class_list":["post-43263","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-digital-services","category-webdevelopment"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.2 (Yoast SEO v27.8) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>wp2shell zwingt WordPress Websites zum Update<\/title>\n<meta name=\"description\" content=\"Die Sicherheitsl\u00fccke wp2shell erlaubt unautorisierten Codezugriff auf WordPress Seiten. Wir zeigen, was jetzt zu tun ist.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/csw.agency\/en\/wp2shell-wordpress\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"wp2shell zwingt WordPress Websites zum Update\" \/>\n<meta property=\"og:description\" content=\"Die Sicherheitsl\u00fccke wp2shell erlaubt unautorisierten Codezugriff auf WordPress Seiten. Wir zeigen, was jetzt zu tun ist.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/csw.agency\/en\/wp2shell-wordpress\/\" \/>\n<meta property=\"og:site_name\" content=\"CSW.AGENCY\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-23T15:10:20+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-23T16:21:31+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/csw.agency\/wp-content\/uploads\/shutterstock_2008881197-scaled.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1707\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"reynders\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"reynders\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"wp2shell forces WordPress websites to update","description":"The wp2shell security vulnerability allows unauthorized code access to WordPress sites. We show what to do now.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/csw.agency\/en\/wp2shell-wordpress\/","og_locale":"en_US","og_type":"article","og_title":"wp2shell zwingt WordPress Websites zum Update","og_description":"Die Sicherheitsl\u00fccke wp2shell erlaubt unautorisierten Codezugriff auf WordPress Seiten. Wir zeigen, was jetzt zu tun ist.","og_url":"https:\/\/csw.agency\/en\/wp2shell-wordpress\/","og_site_name":"CSW.AGENCY","article_published_time":"2026-07-23T15:10:20+00:00","article_modified_time":"2026-07-23T16:21:31+00:00","og_image":[{"width":2560,"height":1707,"url":"https:\/\/csw.agency\/wp-content\/uploads\/shutterstock_2008881197-scaled.jpg","type":"image\/jpeg"}],"author":"reynders","twitter_card":"summary_large_image","twitter_misc":{"Written by":"reynders","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/csw.agency\/wp2shell-wordpress\/#article","isPartOf":{"@id":"https:\/\/csw.agency\/wp2shell-wordpress\/"},"author":{"name":"reynders","@id":"https:\/\/csw.agency\/#\/schema\/person\/c5ff123c81b42e56d3ac99e990134516"},"headline":"wp2shell zwingt WordPress Websites zum Update","datePublished":"2026-07-23T15:10:20+00:00","dateModified":"2026-07-23T16:21:31+00:00","mainEntityOfPage":{"@id":"https:\/\/csw.agency\/wp2shell-wordpress\/"},"wordCount":1107,"publisher":{"@id":"https:\/\/csw.agency\/#organization"},"image":{"@id":"https:\/\/csw.agency\/wp2shell-wordpress\/#primaryimage"},"thumbnailUrl":"https:\/\/csw.agency\/wp-content\/uploads\/shutterstock_2008881197-scaled.jpg","articleSection":["Digital Services","Webdevelopment"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/csw.agency\/wp2shell-wordpress\/","url":"https:\/\/csw.agency\/wp2shell-wordpress\/","name":"wp2shell forces WordPress websites to update","isPartOf":{"@id":"https:\/\/csw.agency\/#website"},"primaryImageOfPage":{"@id":"https:\/\/csw.agency\/wp2shell-wordpress\/#primaryimage"},"image":{"@id":"https:\/\/csw.agency\/wp2shell-wordpress\/#primaryimage"},"thumbnailUrl":"https:\/\/csw.agency\/wp-content\/uploads\/shutterstock_2008881197-scaled.jpg","datePublished":"2026-07-23T15:10:20+00:00","dateModified":"2026-07-23T16:21:31+00:00","description":"The wp2shell security vulnerability allows unauthorized code access to WordPress sites. We show what to do now.","breadcrumb":{"@id":"https:\/\/csw.agency\/wp2shell-wordpress\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/csw.agency\/wp2shell-wordpress\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/csw.agency\/wp2shell-wordpress\/#primaryimage","url":"https:\/\/csw.agency\/wp-content\/uploads\/shutterstock_2008881197-scaled.jpg","contentUrl":"https:\/\/csw.agency\/wp-content\/uploads\/shutterstock_2008881197-scaled.jpg","width":2560,"height":1707,"caption":"Das blaue WordPress-Logo erscheint auf einem Smartphone-Display mit der Beschriftung WordPress. Der enge Ausschnitt betont die digitale Oberfl\u00e4che."},{"@type":"BreadcrumbList","@id":"https:\/\/csw.agency\/wp2shell-wordpress\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Startseite","item":"https:\/\/csw.agency\/"},{"@type":"ListItem","position":2,"name":"Webdevelopment","item":"https:\/\/csw.agency\/category\/webdevelopment\/"},{"@type":"ListItem","position":3,"name":"wp2shell zwingt WordPress Websites zum Update"}]},{"@type":"WebSite","@id":"https:\/\/csw.agency\/#website","url":"https:\/\/csw.agency\/","name":"CSW.AGENCY","description":"Ready For The Future","publisher":{"@id":"https:\/\/csw.agency\/#organization"},"alternateName":"CSW","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/csw.agency\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/csw.agency\/#organization","name":"CSW.AGENCY","alternateName":"CSW","url":"https:\/\/csw.agency\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/csw.agency\/#\/schema\/logo\/image\/","url":"https:\/\/csw.agency\/wp-content\/uploads\/csw_quadrat_blau_HQ2.webp","contentUrl":"https:\/\/csw.agency\/wp-content\/uploads\/csw_quadrat_blau_HQ2.webp","width":1000,"height":1000,"caption":"CSW.AGENCY"},"image":{"@id":"https:\/\/csw.agency\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.instagram.com\/csw.agency\/"],"description":"Digital agency from D\u00fcsseldorf with a focus on SEO, GEO, SEA web development &amp; web design","email":"hello@csw.agency","telephone":"+49 (0) 211 781 777 4 0","legalName":"CSW.AGENCY e.K.","foundingDate":"2011-01-01","vatID":"DE299330840","numberOfEmployees":{"@type":"QuantitativeValue","minValue":"1","maxValue":"10"}},{"@type":"Person","@id":"https:\/\/csw.agency\/#\/schema\/person\/c5ff123c81b42e56d3ac99e990134516","name":"reynders","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/353ec5f589898cbe8aa32096ec97db1e2afacf38520e2f99d1853713c4eec477?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/353ec5f589898cbe8aa32096ec97db1e2afacf38520e2f99d1853713c4eec477?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/353ec5f589898cbe8aa32096ec97db1e2afacf38520e2f99d1853713c4eec477?s=96&d=mm&r=g","caption":"reynders"}}]}},"modified_by":"reynders","_links":{"self":[{"href":"https:\/\/csw.agency\/en\/wp-json\/wp\/v2\/posts\/43263","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/csw.agency\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/csw.agency\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/csw.agency\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/csw.agency\/en\/wp-json\/wp\/v2\/comments?post=43263"}],"version-history":[{"count":6,"href":"https:\/\/csw.agency\/en\/wp-json\/wp\/v2\/posts\/43263\/revisions"}],"predecessor-version":[{"id":43271,"href":"https:\/\/csw.agency\/en\/wp-json\/wp\/v2\/posts\/43263\/revisions\/43271"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/csw.agency\/en\/wp-json\/wp\/v2\/media\/43265"}],"wp:attachment":[{"href":"https:\/\/csw.agency\/en\/wp-json\/wp\/v2\/media?parent=43263"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/csw.agency\/en\/wp-json\/wp\/v2\/categories?post=43263"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/csw.agency\/en\/wp-json\/wp\/v2\/tags?post=43263"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}