wp2shell: Public exploits for WordPress Core RCE - patch now

Cybersecurity Sep 2, 2026Add to bookmarks

wp2shell: Public exploits for WordPress Core RCE - patch now
Illustration : Momiji Shirogane

The wp2shell vulnerability in WordPress Core allows unauthenticated remote code execution. Public exploits are circulating. If your installation isn't up to date, you're at risk—and 43% of the web runs on WordPress.

What: Unauthenticated RCE in WordPress Core

wp2shell refers to a series of critical vulnerabilities in WordPress Core enabling remote code execution (RCE) without authentication. In concrete terms: an attacker can execute arbitrary code on your server without having any account on your site.

WordPress versions 6.9 and 7.0 are affected. Public exploits are now circulating. The response window is narrow—any unpatched installation is an exposed target.

Who is impacted

Any WordPress installation running version 6.9 or 7.0 that has not been updated to the patched versions. WordPress powers about 43% of websites globally. Even a personal blog can serve as a stepping stone for attacks on other targets or be integrated into a botnet.

Particularly at risk:

  • Sites with automatic updates disabled
  • Shared hosting environments with delayed updates by the provider
  • Abandoned or poorly maintained installations

What to do now

  1. Update to WordPress 6.9.5 or 7.0.2 minimum – these versions patch wp2shell (Dashboard → Updates)
  2. Check access logs for suspicious requests to affected endpoints (details in WordPress Security advisories)
  3. Enable automatic core updates – add define('WP_AUTO_UPDATE_CORE', true); to wp-config.php
  4. If using shared hosting: contact your host to confirm the update has been applied server-side

What wp2shell is (and what it isn't)

wp2shell is exclusively an RCE flaw in the WordPress core (WordPress Core). It is not a malicious plugin, an AI agent, or a supply chain attack. It is a vulnerability in WordPress’s own code, remotely exploitable without an account. The fix is straightforward: update to 6.9.5 or 7.0.2.

What to do now

Update WordPress Core to 6.9.5 or 7.0.2. Check access logs. If you manage multiple WordPress sites for clients, prioritize them immediately—exploits are public and large-scale automated exploitation is a matter of hours.

Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

SSHSelf-hostedAI Ops
Get early access
Was this article helpful?

9 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

Get early access
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information