1. Home
  2. Security Blog
  3. 20-07-2026 – Urgent check your WordPress version now wp2shell CVE-2026-60137 CVE-2026-63030

20-07-2026 – Urgent check your WordPress version now wp2shell CVE-2026-60137 CVE-2026-63030

Urgent security notice. Two serious vulnerabilities in WordPress core (CVE-2026-60137 and CVE-2026-63030, known together as “wp2shell”) allow an attacker to take over a WordPress website with no username, no password and no user interaction. Working exploit code is publicly available and attacks are already being seen in the wild. If you run WordPress, please check your version today.

What has happened

On 17 July 2026 the WordPress security team released an emergency update fixing two flaws that can be chained together:

  • CVE-2026-60137 – a SQL injection flaw in the author__not_in parameter of WP_Query.
  • CVE-2026-63030 – a REST API batch-route confusion flaw introduced in WordPress 6.9.

Individually they are serious. Combined, they give an unauthenticated attacker remote code execution – the ability to run their own code on your website. The researchers who found the chain (Searchlight Cyber) confirmed it works against a stock WordPress install with no plugins at all.

Why this is being treated as critical

This is not a theoretical risk. In practice, a successful attack can mean:

  • Your entire database read and copied, including usernames, email addresses and password hashes.
  • New administrator accounts created for the attacker, giving them permanent access.
  • Malicious plugins or web shells uploaded, so they can run commands on the server.
  • Your site defaced, used to serve malware or spam, or your customer data stolen.

In short: a full site takeover. Because no login is required, automated bots can scan and attack large numbers of sites indiscriminately – it does not matter how small or low-profile your website is.

Proof-of-concept exploit code has been published publicly, and security researchers have already reported exploitation happening in the wild. The window between “vulnerability announced” and “sites being attacked” has effectively closed. Please treat this as urgent.

Am I affected?

Check your WordPress version against this table:

Your WordPress versionStatusUpdate to
7.0.0 – 7.0.1Vulnerable to the full takeover chain7.0.2
6.9.0 – 6.9.4Vulnerable to the full takeover chain6.9.5
6.8.0 – 6.8.5Vulnerable to the SQL injection flaw6.8.6
7.0.2, 6.9.5, 6.8.6 or newerPatched – no action needed

Versions 6.8.0 to 6.8.5 are affected by the SQL injection flaw but not the full remote code execution chain, because the REST API flaw was only introduced in WordPress 6.9. This is still a high-severity issue that can expose your database, so please update.

How to check which WordPress version you are running

There are a few easy ways to check. Any one of them will do.

From your WordPress dashboard

  1. Log in to your site at yourdomain.com/wp-admin.
  2. On the main Dashboard screen, find the At a Glance box.
  3. It will say something like “WordPress 7.0.2 running Twenty Twenty-Six theme”. That number is your version.

You can also see your version in the bottom right corner of any WordPress admin page, or by going to Dashboard > Updates, which shows your current version and offers any available update.

From your Enhance panel

  1. Log in to your Enhance panel.
  2. Select the website you want to check.
  3. Open the WordPress section, where your installed version is displayed.

What to do right now

If you are on any affected version, update immediately.

  1. Log in to yourdomain.com/wp-admin.
  2. Go to Dashboard > Updates.
  3. Click Update to version … and wait for it to finish.
  4. Return to At a Glance and confirm the version number has changed.

Because of the severity, WordPress.org has enabled forced automatic updates for sites running affected versions. Many sites will already have been patched automatically – but you should still check rather than assume, as automatic updates can be disabled or can fail.

Turn on automatic security updates

Once you are patched, make sure automatic updates for minor and security releases are enabled so you are protected the next time something like this happens. You will find this under Dashboard > Updates.

Signs your site may already have been compromised

Updating fixes the hole, but it does not undo damage done beforehand. If your site was running a vulnerable version while exploits were circulating, please also check for:

  • Unfamiliar administrator accounts under Users – a very common sign.
  • Plugins you do not recognise, particularly any that are installed but not active.
  • Unexpected redirects, pop-ups, or spam content appearing on your pages.
  • Unexplained changes to files, or new files in your uploads folder.
  • Search engines or your browser warning that your site is unsafe.

If you see any of these signs, please contact our support team straight away rather than simply deleting what you find. An attacker who gained access may have left more than one way back in, and we can help you check properly and restore from a clean backup if needed.

How Patchstack helps protect you

Updating promptly is the single most important thing you can do, and no security product replaces it. The difficulty for most site owners is the gap in between: a vulnerability is announced, exploits appear within hours, and your site sits exposed until someone notices and applies the update.

That gap is what Patchstack is designed to close. It works alongside WordPress, not instead of updating, and it gives you:

  • Virtual patching. Patchstack can block known exploit attempts before they reach your site, which protects you during the window before an update is applied – and for cases where a vulnerable plugin has no fix available yet.
  • Continuous vulnerability monitoring. It tracks the version of WordPress core, and every plugin and theme you run, against a live vulnerability database and tells you the moment something you use becomes vulnerable.
  • Alerts you will actually see. Rather than you needing to follow security news, you get notified about issues that affect your specific site.
  • Hardening and reporting, so you can see the security posture of your site at a glance.

For an incident like wp2shell, the practical benefit is time: you find out you are affected immediately, and known attacks against your site can be blocked while you get updated.

To be clear, Patchstack is a layer of protection, not a substitute for keeping WordPress up to date. Even with it in place, you should still apply the update above.

Getting Patchstack from PAC

You can buy a Patchstack site licence directly from us, and we will install and configure it on your website for you – there is nothing technical for you to do.

Order a Patchstack site licence

If you have questions about which licence you need, or you have several websites, please open a sales ticket and we will advise.

Not sure what version you are on, unsure whether your site updated correctly, or worried your site may have been affected? Please contact our support team. We would much rather check for you than have you left exposed.

Updated on July 20, 2026
Was this article helpful?
Need Support?
Can't find the answer you're looking for? Don't worry we're here to help!
GET SOME HELP!