07/30/2026
Critical WordPress Security Alert — "WP2Shell"
A critical vulnerability chain in WordPress core (CVE-2026-60137 + CVE-2026-63030), dubbed WP2Shell, is being actively exploited right now. It lets attackers take over a vulnerable site completely with no login, no special conditions required.
Please note: This is not an issue with our hosting platform or servers, it is a vulnerability in the WordPress application itself, affecting WordPress sites worldwide regardless of where they are hosted. We're sharing this so our customers can protect their sites.
Who is affected?Any site running WordPress 6.9.0–6.9.4 or 7.0.0–7.0.1. This is a WordPress core issue; it doesn't depend on any particular plugin or theme.
What should you do?
Check your version now: log in to your WordPress dashboard → Dashboard → Updates and Update immediately to 6.9.5 or 7.0.2 (or newer). WordPress has pushed automatic updates but don't assume it worked. If auto-updates are disabled on your site, you must update manually. After updating, change your WordPress admin passwords as a precaution, attackers have been harvesting credentials from unpatched sites.
Not sure, or need a hand? Open a support ticket and our team will check your WordPress version, apply the update, and review your site for any signs of compromise.
Don't wait on this one, patch today.