On 17 July 2026, security researchers disclosed two flaws in WordPress core - tracked as CVE-2026-63030 and CVE-2026-60137 - which when chained together let an attacker with no account, no password, and no plugin needed take full control of a WordPress site remotely. WordPress.org shipped emergency patches the same day (versions 6.8.6, 6.9.5, or 7.0.2 depending on which release line a site was on) and pushed them out as forced automatic updates.
Within days, multiple independent security firms confirmed real-world exploitation: attackers used the flaw to create over 100 fake administrator accounts, install malicious plugins, and in some cases plant remote-access malware. Exact current numbers of compromised sites are not settled. One industry sample of roughly 125,000 sites found about 82 percent had been patched as of early August - meaning a meaningful minority were still exposed - and the full scale of successful break-ins has not been independently tallied.
Why it matters if you run a business
WordPress runs a very large share of small business websites worldwide, whether built directly, through a web host's one-click installer, or by a freelancer or agency who set it up and moved on. This bug did not require a stolen password or a targeted attack. It worked against any unpatched site sitting on the open internet - exactly the kind of quiet, unglamorous website a small business owns and rarely thinks about after launch.
The practical risk is not just defacement. A compromised site can be used to serve malware to your own customers, get blacklisted by Google and browsers (which kills search traffic and shows visitors a dangerous-site warning), or quietly host a backdoor an attacker returns to later. If nobody has actively checked whether your site auto-updated, that is worth resolving this week rather than assuming your host handled it.
Questions worth asking
- Has our WordPress site - or our web host or agency - applied the July 2026 security update (version 6.9.5, 7.0.2, or 6.8.6 depending on what we were running)?
- Do we have WordPress automatic updates switched on, or does someone have to remember to update it manually?
- Even if we think we are patched, can someone check the site for administrator accounts we do not recognise, or plugins we did not install, as a precaution?
One security sample found roughly 18 percent of WordPress sites were still unpatched against a bug that needs no password to take over a site - weeks after the fix shipped as an automatic update.
Sources
- The Hacker News: New wp2shell WordPress Core Flaw
- The Hacker News: wp2shell Exploitation Grows
- Coalition Security Labs: WP2Shell Vulnerabilities Exploited in the Wild
- BleepingComputer: Critical wp2shell WordPress flaws exploited
- Wiz: Exploitation in the Wild of wp2shell
The fast way to check the rest
Patching WordPress is step one. AuditCrow's free scan then checks the technical foundations of the page itself - HTTPS, redirects, robots, and more - so you can see what else is quietly broken after the emergency update.