What has happened
On 17 July 2026 the WordPress security team released an emergency update fixing two flaws that can be chained together:
- CVE-2026-60137 – a SQL injection flaw in the author__not_in parameter of WP_Query.
- CVE-2026-63030 – a REST API batch-route confusion flaw introduced in WordPress 6.9.
Individually they are serious. Combined, they give an unauthenticated attacker remote code execution – the ability to run their own code on your website. The researchers who found the chain (Searchlight Cyber) confirmed it works against a stock WordPress install with no plugins at all.
Why this is being treated as critical
This is not a theoretical risk. In practice, a successful attack can mean:
- Your entire database read and copied, including usernames, email addresses and password hashes.
- New administrator accounts created for the attacker, giving them permanent access.
- Malicious plugins or web shells uploaded, so they can run commands on the server.
- Your site defaced, used to serve malware or spam, or your customer data stolen.
In short: a full site takeover. Because no login is required, automated bots can scan and attack large numbers of sites indiscriminately – it does not matter how small or low-profile your website is.
Am I affected?
Check your WordPress version against this table:
| Your WordPress version | Status | Update to |
|---|---|---|
| 7.0.0 – 7.0.1 | Vulnerable to the full takeover chain | 7.0.2 |
| 6.9.0 – 6.9.4 | Vulnerable to the full takeover chain | 6.9.5 |
| 6.8.0 – 6.8.5 | Vulnerable to the SQL injection flaw | 6.8.6 |
| 7.0.2, 6.9.5, 6.8.6 or newer | Patched – no action needed | – |
How to check which WordPress version you are running
There are a few easy ways to check. Any one of them will do.
From your WordPress dashboard
- Log in to your site at yourdomain.com/wp-admin.
- On the main Dashboard screen, find the At a Glance box.
- It will say something like “WordPress 7.0.2 running Twenty Twenty-Six theme”. That number is your version.
From your Enhance panel
- Log in to your Enhance panel.
- Select the website you want to check.
- Open the WordPress section, where your installed version is displayed.
What to do right now
If you are on any affected version, update immediately.
- Log in to yourdomain.com/wp-admin.
- Go to Dashboard > Updates.
- Click Update to version … and wait for it to finish.
- Return to At a Glance and confirm the version number has changed.
Turn on automatic security updates
Once you are patched, make sure automatic updates for minor and security releases are enabled so you are protected the next time something like this happens. You will find this under Dashboard > Updates.
Signs your site may already have been compromised
Updating fixes the hole, but it does not undo damage done beforehand. If your site was running a vulnerable version while exploits were circulating, please also check for:
- Unfamiliar administrator accounts under Users – a very common sign.
- Plugins you do not recognise, particularly any that are installed but not active.
- Unexpected redirects, pop-ups, or spam content appearing on your pages.
- Unexplained changes to files, or new files in your uploads folder.
- Search engines or your browser warning that your site is unsafe.
How Patchstack helps protect you
Updating promptly is the single most important thing you can do, and no security product replaces it. The difficulty for most site owners is the gap in between: a vulnerability is announced, exploits appear within hours, and your site sits exposed until someone notices and applies the update.
That gap is what Patchstack is designed to close. It works alongside WordPress, not instead of updating, and it gives you:
- Virtual patching. Patchstack can block known exploit attempts before they reach your site, which protects you during the window before an update is applied – and for cases where a vulnerable plugin has no fix available yet.
- Continuous vulnerability monitoring. It tracks the version of WordPress core, and every plugin and theme you run, against a live vulnerability database and tells you the moment something you use becomes vulnerable.
- Alerts you will actually see. Rather than you needing to follow security news, you get notified about issues that affect your specific site.
- Hardening and reporting, so you can see the security posture of your site at a glance.
For an incident like wp2shell, the practical benefit is time: you find out you are affected immediately, and known attacks against your site can be blocked while you get updated.
Getting Patchstack from PAC
You can buy a Patchstack site licence directly from us, and we will install and configure it on your website for you – there is nothing technical for you to do.
Order a Patchstack site licence
If you have questions about which licence you need, or you have several websites, please open a sales ticket and we will advise.