Back

WordPress Releases Emergency Patch for Critical wp2shell Vulnerability

At a glance

  • WordPress 7.0.2 update released on July 17, 2026.
  • Critical vulnerability allows unauthenticated remote code execution.
  • Active exploitation reported within hours of disclosure.

WordPress issued an urgent security update on July 17, 2026, to address a critical vulnerability that allowed attackers to execute code on affected websites. The release responded to confirmed exploitation attempts targeting unpatched systems.

The security update, version 7.0.2, fixed two vulnerabilities: one classified as critical and another as high severity. The critical flaw, tracked as CVE-2026-63030, involved a combination of REST API batch-route confusion and a SQL injection (CVE-2026-60137), which together enabled attackers to run arbitrary code without authentication.

This vulnerability chain, referred to as “wp2shell,” could be used by an unauthenticated attacker to gain control over WordPress installations. Patchstack independently verified that the combined vulnerabilities could result in a full site takeover, including remote code execution capabilities.

Multiple security companies confirmed that exploitation began shortly after the vulnerability details were made public. Proof-of-concept exploits appeared online within hours of the July 17 announcement, and exploit attempts were detected within approximately 90 minutes of the patch release.

What the numbers show

  • WordPress 7.0.2 was released on July 17, 2026.
  • Exploit attempts observed within 90 minutes of patch availability.
  • Two vulnerabilities addressed: CVE-2026-63030 (critical) and CVE-2026-60137 (high severity.

Cloudflare responded to the disclosure by deploying Web Application Firewall protections on July 17, 2026. These measures aimed to reduce exposure to the remote code execution and SQL injection vulnerabilities while users applied the official update.

Security firms stated that proof-of-concept code for the wp2shell vulnerability was publicly available soon after the update was released. This rapid availability increased the risk for sites that had not yet installed the patch.

According to the CUHK Information Technology Services Centre, the wp2shell vulnerability allowed attackers to execute arbitrary code on affected WordPress sites without requiring authentication. This made timely patching essential for site operators.

Industry reaction

Cloudflare announced the deployment of Web Application Firewall rules to help protect WordPress sites from exploitation attempts as soon as the vulnerabilities were disclosed.

Patchstack confirmed through independent verification that the vulnerabilities could allow a full site takeover, emphasizing the importance of applying the security update promptly.

* This article is based on publicly available information at the time of writing.