Filed under: Cybersecurity · Patching · July 2026

What happened

On July 17, 2026, WordPress disclosed a critical flaw nicknamed “wp2shell” that lets an attacker take over a website with no password and no login at all. It chains two bugs in WordPress core itself (CVE-2026-63030, a REST API confusion, and CVE-2026-60137, a database-injection bug) so that a single anonymous web request can steal data and then run the attacker’s own code on the server. Within a day, automated attacks were scanning the internet for vulnerable sites, and researchers had verified more than two dozen working exploits by July 19. The flaw affects WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1; the fixes are in versions 6.9.5 and 7.0.2.

Why it matters to your business

Most Phoenix small businesses run their website on WordPress — it powers roughly four in ten sites on the internet — and this is a hole in WordPress itself, not some add-on plugin, so nearly every WordPress site was exposed the moment the details went public. One analysis found that 60% of organizations using WordPress had at least one vulnerable site. A hijacked site can be defaced, quietly used to push malware to your own customers, or turned into a doorway to your booking forms, contact-form data, and connected email. Because the attack needs no login, criminals are hitting thousands of sites automatically rather than picking targets by hand.

What to do this week

Update WordPress today. Log in to your site’s admin dashboard, go to Dashboard → Updates, and click “Update Now” — if you’re on a 6.9.x version get to 6.9.5, and if you’re on 7.0.x get to 7.0.2 (or newer). Many hosts such as WP Engine, Bluehost, and GoDaddy auto-apply minor core updates, so confirm yours actually did by checking the version number at the bottom of that Updates page. If you’re not sure who manages your website, or it hasn’t been touched in months, have someone verify the version now and look for unexpected new administrator accounts or unfamiliar files. Any site that sat on a vulnerable version while exposed to the internet after July 17 should be treated as possibly probed — scan it for signs of compromise, not just patched and forgotten.

The bigger picture

Your public website needs the same patch discipline as the laptops in your office — attackers automate their scanning and move within hours of a public exploit, so “we’ll get to it next week” is the same as leaving the front door unlocked overnight. Staying current on a schedule is far cheaper than cleaning up a defaced or malware-serving site after the fact. Proactive vs. Reactive IT Management: Lessons from Healthcare for SMBs

Not sure whether your company website is patched and safe? Book a free consult → https://micro1tech.com/contact/