Security

wp2shell: the critical WordPress vulnerability you need to patch now

A chain of two flaws in WordPress core lets an attacker take control of a site without needing a password or a vulnerable plugin. Here's what you need to check.

Published on August 13, 2026 · The mitza.es team

In mid-July 2026, a chain of critical vulnerabilities in WordPress core, dubbed wp2shell, was made public. Spain's national cybersecurity institute, INCIBE, issued an urgent alert on Monday, July 20, at 11:50 AM, and just hours after the patches were released, active exploitation attempts were already being detected — fairly typical once a vulnerability of this level goes public.

What makes this vulnerability especially serious

The chain combines two flaws identified as CVE-2026-63030 and CVE-2026-60137, present in the 6.9.x and 7.0.x branches of WordPress core. What makes it more dangerous than a typical plugin vulnerability is that it doesn't depend on any additional plugin or theme: a remote attacker can execute code on the server without needing to authenticate, by combining both flaws directly against the CMS core.

Which versions are affected

  • WordPress 6.9.0 to 6.9.4: affected by the full chain.
  • WordPress 7.0.0 to 7.0.1: affected by the full chain.
  • WordPress 6.8: only vulnerable to the SQL injection part, not the full remote-code-execution chain.

How to protect yourself right now

INCIBE and the WordPress community itself recommend updating immediately to versions 6.9.5, 6.8.6 or 7.1 beta2, depending on the branch you use. As a temporary measure while the update is applied, it's recommended to restrict anonymous access to the site's REST API, one of the points the chain exploits to operate without authentication.

Why this puts basic maintenance back on the table

WordPress powers a very significant share of SME and freelancer websites in Spain, and this kind of vulnerability is a reminder that maintenance isn't an optional expense. A site that goes weeks without updates is, literally, an open door. This connects directly with the rise in ransomware we've seen this year in Spain: many attacks start precisely with an unpatched CMS. If you're not sure which version your site is on or who's responsible for keeping it up to date, our IT maintenance service includes this review, and if you're considering leaving behind a problematic WordPress installation, we can also propose a more controlled custom development.

Do you know if your WordPress is on an affected version?

We check your installation, apply the necessary patches, and reinforce basic security.

No spam. No sales calls. Just your personalised reply.