Two vulnerabilities in the WordPress core, collectively known as wp2shell (CVE-2026-63030 and CVE-2026-60137), allow a site to be completely taken over with a single request, without a password. This isn’t some exotic plugin: the attack works on a standard installation, and for small businesses that run their websites on WordPress, this poses an immediate risk.
After the exploit code was published, researchers at watchTowr counted tens of thousands of attempts, and on the compromised sites, the attackers created over 100 hidden administrator accounts. Herein lies the main trap: an administrator account left behind remains functional even after you update. The update closes the vulnerability, but it does not clean up a site that has already been compromised.
The secure versions are 6.9.5 and 7.0.2, released on July 17. Any installation between 6.9.0 and 6.9.4 or between 7.0.0 and 7.0.1 is vulnerable.
Three checks you can perform from the admin panel without any technical knowledge:
- Check your WordPress version and update to 6.9.5 or 7.0.2.
- Under "Users," delete any administrator accounts you don't recognize.
- Under Plugins, uninstall anything you didn’t install yourself.
If the website was online but not updated in the days following the disclosure of the vulnerability, treat it as potentially compromised: in addition to the checks listed above, you should change the passwords for the admin accounts and verify who else has access to the hosting account. If there’s no one in the company who can perform this check, now is the right time to ask for help.
The article on which this information is based:
- The Hacker News | https://thehackernews.com/2026/07/wordpress-wp2shell-exploitation-grows.html
This article was generated with AI assistance.