July 22, 2026
WP2Shell: vulnerabilità di sicurezza WordPress

We don’t want to scare you, but we also don’t want to beat around the bush: On July 17, 2026, one of the most serious vulnerabilities to affect WordPress in recent years was discovered.

It’s called WP2Shell, and shortly after the security updates were released, several researchers began detecting actual exploitation attempts targeting sites that hadn’t yet been updated. The situation warrants attention, but the good news is that a solution already exists and that we took immediate action on the systems we manage.

First of all: if your website is hosted with us, you can rest assured

If your website is hosted on Isola or is covered by one of our maintenance agreements, we have already applied the necessary updates and security measures.

We have verified the versions of WordPress installed, updated the affected systems, and stepped up monitoring of suspicious requests. We will continue to monitor the situation as it develops and will take further action should new information come to light.

In other words: you don’t need to rush to update anything, install random plugins, or look for solutions you found on some forum. We’re taking care of it.

What is WP2Shell?

WP2Shell is the name given to a chain of two vulnerabilities in the WordPress core, identified as CVE-2026-60137 and CVE-2026-63030.

This distinction is important: we’re not talking about the usual problem caused by an outdated plugin, an abandoned theme, or a password that’s too simple. The vulnerabilities are found directly in the core WordPress software and can be exploited even on a standard installation—without any vulnerable plugins and without the attacker first needing to gain access.

If exploited together, these two vulnerabilities could allow an attacker to gain administrative privileges and execute code on the server. In less technical terms, this means that an unpatched website could be compromised, used to install a backdoor, redirect visitors, or carry out other malicious activities.

Which versions are affected?

The versions most affected by the full WP2Shell chain are:

  • WordPress versions 6.9.0 through 6.9.4;
  • WordPress 7.0.0 and 7.0.1.

The bugfix updates are WordPress 6.9.5 and 7.0.2.

WordPress versions 6.8.0 through 6.8.5 also contain one of the two vulnerabilities—an SQL injection—but are not vulnerable to the full remote code execution chain. A fixed version, 6.8.6, has been released for this release line. Versions prior to 6.8 are not affected by these specific vulnerabilities.

On July 17, 2026, the WordPress team classified the issues as one critical and one high-severity, recommending an immediate update. Given the seriousness of the situation, WordPress also enabled forced automatic updates on compatible sites. This helps a lot, but it doesn’t mean that all sites have been updated correctly: specific configurations, incorrect permissions, or disabled automatic updates can prevent the patch from being installed.

Are the attacks really happening?

Yes, but it is more accurate to speak of numerous scanning and exploitation activities carried out by different actors, rather than necessarily a single large-scale coordinated attack.

Wordfence detected the first attempts to exploit these vulnerabilities within hours of the updates being released. Wiz subsequently documented successful compromises, the installation of malicious plugins, access to administrative panels, and the uploading of webshells—tools that allow attackers to maintain control of the server.

On July 21, CISA, the U.S. Cybersecurity and Infrastructure Security Agency, also added both vulnerabilities to its list of actively exploited vulnerabilities. This is further confirmation that this is not merely a theoretical risk.

The speed with which attack attempts began is not surprising. After a security update is released, researchers and cybercriminals can compare the old code with the patched version and figure out how the vulnerability works. For this reason, in the field of security, the hours immediately following a public announcement are often the most critical.

Why is the problem so widespread?

WordPress continues to be used by a huge portion of the web. According to W3Techs data updated as of July 22, 2026, it is used on approximately 41% of the sites analyzed and accounts for nearly 60% of the content management system market.

When a vulnerability affects the core of such a widely used platform, the potential attack surface becomes very large. At the same time, WordPress’s widespread adoption also means that there is an international community of developers, researchers, hosting providers, and security firms ready to collaborate and respond quickly.

In this case, the vulnerabilities were responsibly reported to the WordPress team before they were made public. The fixed versions were therefore already available by the time the issue became known.

And what does artificial intelligence have to do with it?

This is where the story gets particularly interesting.

The researcher who discovered WP2Shell said he used an advanced OpenAI model to assist with code analysis and the search for the vulnerability. In this case, therefore, artificial intelligence served as a defensive tool: it helped an expert identify a problem and report it responsibly before it was made public.

This does not mean that AI cannot also be used for malicious activities. OpenAI and Anthropic have published several reports describing attempts to use their systems for phishing, malware development, vulnerability research, and other malicious activities. Both companies state that they have identified and blocked accounts involved in such abuses.

The issue, however, cannot be reduced to the claim that “artificial intelligence is dangerous.” These models did not invent cyberattacks, nor do they automatically replace the expertise of a professional. They can, however, speed up certain operations, automate repetitive tasks, and make certain tools more accessible.

This applies to those who attack, but also to those who defend.

Artificial intelligence can help examine large amounts of code, detect anomalies, analyze logs, identify vulnerabilities, and respond more quickly to incidents. The real challenge is not to avoid the technology, but to use it responsibly, competently, and with appropriate controls in place.

What Should Someone Who Manages a WordPress Site on Their Own Do?

Anyone who does not have a managed hosting service or a maintenance agreement should check the installed version immediately.

It’s not enough to assume that the automatic update has taken place; you need to check the WordPress dashboard. The correct versions are 6.8.6, 6.9.5, and 7.0.2, depending on the branch you’re using.

After the update, it’s also a good idea to check:

  • the presence of unknown administrator users;
  • plugins that have been recently installed or modified;
  • PHP files created or modified for no apparent reason;
  • unusual access attempts and suspicious requests to the REST APIs;
  • the proper functioning of the backups.

An application firewall can reduce the risk and block some attempts, but it is no substitute for updating the core. If you suspect that the site has already been compromised, updating WordPress is not enough: you need to perform a thorough check, change your credentials, and verify the integrity of the files and the database.

Don’t panic, but don’t wing it either

WP2Shell is a serious problem. It would be wrong to downplay it, just as it would be wrong to describe it as the end of WordPress or as an inevitable attack on every website.

A fix is available and has already been released. The risk primarily affects systems that are still running vulnerable versions or those that may have been compromised by attackers before the update was installed.

It is precisely in situations like this that you can see the difference between simply having a website online and having a website that is maintained, updated, and monitored over time.

If your site is hosted on Isola or is covered by our maintenance service, we have already taken the necessary measures and are continuing to monitor the situation.

You can keep working without worrying.

We’re here.

Random image
Random image

What's New: Google Premier Partners 2025 Awarded!

We fall within the top 3% of the best performing agencies in Italy 🚀