WordPress security vulnerability hacker cyberattack website

We Patched wp2shell in 4 Hours. On a Friday Afternoon.

By John Locke on July 21, 2026
Sustainable/Open Business

On July 17, WordPress shipped an emergency security release for a vulnerability chain now being called wp2shell. It's about as bad as WordPress vulnerabilities get: an anonymous attacker can take full control of a default WordPress install, with no plugin required, no login, and no misconfiguration to find. Just a crafted request against the REST API. As of this week, that's no longer a theoretical risk. Active exploitation is confirmed, and unpatched sites are being hit right now. If your WordPress site is still running an affected version, the question isn't whether it's a target. It's whether someone's already gotten in.

What Actually Happened

wp2shell isn't one bug, it's two, chained together. The first, CVE-2026-60137, is a SQL injection buried in a core WordPress query class, a flaw that reaches all the way back to WordPress 6.8. The second, CVE-2026-63030, is a routing confusion issue in the REST API's batch endpoint, a feature that's been part of WordPress core since 2020. Neither one is catastrophic alone. Chained, they let an attacker write arbitrary PHP files straight onto your server: total compromise, from a single anonymous HTTP request. The affected versions are WordPress 6.9.0 through 7.0.1, with a narrower SQL-injection-only exposure going back to 6.8.x. WordPress patched it fast, releasing 6.9.5 and 7.0.2 the same day the issue became public, and took the unusual step of forcing automatic updates given the severity. But "the patch exists" and "your site got it" are two different facts, and plenty of WordPress installs, especially ones nobody's actively managing, are still sitting exposed. Researchers have since confirmed dozens of distinct proof-of-concept exploits circulating, with attackers already deploying webshells and creating backdoor admin accounts on unpatched sites. You can also check your own site's exposure with the researchers' own public tool at wp2shell.com.

What We Did

Every site we manage was patched within four hours of the security release going out.

The alert landed just before noon on a Friday, Pacific time. That's already past 2pm on the East Coast, and after close of business across most of Europe, the exact window when a lot of teams have mentally checked out for the weekend. Not because we got lucky, or because someone happened to be watching Twitter that afternoon. It's because we ran every affected site through our real deployment pipeline: applied the update on a dev copy with WP-CLI, pushed it through our automated tests, deployed to a staging copy for full visual regression testing, took a complete database snapshot, then rolled it to production. Every step, every site, in four hours, on a Friday afternoon. For a fleet this size, we can push each site through that full process by hand quickly. As we bring more WordPress sites under management, we're building a hotfix path, already proven on our Drupal infrastructure, that skips the full test cycle for releases this severe: snapshot, apply, deploy immediately, then verify. That's what lets us patch a hundred or more sites in a few hours instead of days. It's also why, when we handled a serious security incident on a client site earlier this year, we already had the forensic playbook ready:

  • How to find a planted webshell
  • How to tell a legitimate database entry from a backdoor
  • How to lock things back down properly, instead of just patching the hole that was found

If You're Not Sure Where You Stand

Most WordPress site owners don't know their core version off the top of their head, and even fewer know whether their site shows signs of already having been touched. That's a reasonable thing not to know. It's not your job to track CVEs. It's ours. We're offering a free wp2shell exposure check, available through Friday, July 31, in two parts.

Step one: the free check

Submit your site's URL below and we'll check it from the outside, quickly and safely, with no login and no risk to your site. We'll confirm whether you're running an affected WordPress version and tell you plainly where you stand:

  • You're patched. Good, you're done.
  • You're exposed but we see no signs of compromise. Patch immediately, and let's talk about making sure you're never four days behind on something like this again.
  • Something looks off from the outside and it's worth a closer look.

Step two: if you need it, the deeper look

Confirming an actual compromise, a planted webshell, a backdoor admin account, suspicious code hiding in your database, takes more than an outside glance. If step one comes back exposed, or your gut already says something's wrong, we'll ask for temporary access to your site so we can run the same forensic process we've used for clients before: find what's there, tell you exactly what happened, and clean it up properly. This deeper engagement is a paid service, scoped to what we find, and we'll walk you through exactly what that looks like before anything starts. Given the volume we're expecting, we can take on a limited number of these deeper engagements alongside the free checks. This offer runs through July 31, so if your gut says something's wrong, don't wait to find out.

Free wp2shell Exposure Check

Optional, only if you want a call instead of email
The WordPress site you want checked
This just helps us prioritize. Everyone gets the free version check either way.

Offer ends Friday, July 31. Request your free wp2shell check → 


Freelock has been running open source web infrastructure, Drupal and WordPress, since 2003. If you want the technical detail on how the wp2shell chain works, or how a real deployment pipeline changes incident response timelines, we're happy to talk shop.

Sustainable/Open Business

Add new comment

The content of this field is kept private and will not be shown publicly.

Filtered HTML

  • Web page addresses and email addresses turn into links automatically.
  • Allowed HTML tags: <a href hreflang> <em> <strong> <blockquote cite> <cite> <code> <ul type> <ol start type> <li> <dl> <dt> <dd> <h1> <h2 id> <h3 id> <h4 id> <h5 id> <p> <br> <img src alt height width>
  • Lines and paragraphs break automatically.

Drupal Canvas — Block HTML (locked)

  • Allowed HTML tags: <strong> <em> <u> <a href> <p> <br> <ul> <ol> <li>

Drupal Canvas — Inline HTML (locked)

  • Allowed HTML tags: <strong> <em> <u> <a href>

About the Author

Profile picture for user John Locke

John Locke is the lead developer and founder of Freelock, LLC. In addition to being a proficient web developer, he is an experienced technical writer, network administrator, and all around problem solver. He has worked with computers since 1984, and currently advises small businesses on open source software.

More Like This

AI vulnerabilities, security incidents, resilience, Drupal WordPress, cybersecurity
🕑May 18, 2026 🖋John Locke 💬0

The Rules Have Changed: Security in the Age of AI-Assisted Attacks

Security is getting dramatically harder and more expensive. AI is simultaneously driving an explosion in vulnerability discovery and weaponizing the exploits that follow. The question for every organization with anything online is no longer whether to invest in resilience — it's whether that investment is already in place before the next incident arrives.
Grafana line showing load dropping to normal
🕑Aug 22, 2023 🖋John Locke 💬2

Rate Limiting an aggressive bot in Nginx

High load isn't necessarily an emergency, but it may be a heads-up before a site noticeably slows down. Sometimes there are weird spikes that just go away, but sometimes this is an indication of a Denial of Service.

Code monster
🕑Mar 29, 2018 🖋John Locke 💬3

Drupalgeddon2: Should I worry about critical security updates?

No, you should not. You should let us worry about them, and go back to your business.

Seriously, we're getting questions from all kinds of people about whether this matters. I'm a bit surprised that there is any question about that. Would you be concerned if your top salesperson was selling for somebody else? If your cashiers were jotting down credit card numbers when they charged a card? If your office became a well-known spot for illicit drug or gun dealers? If your office had a bunch of scammers squatting and running a pyramid scheme? If your confidential client information could be revealed as easily as using a bic pen on an old Kryptonite lock?

Bic Pen vs Kryptonite Lock

We've seen some variation of every single one of those scenarios. And all of them are possible with a remote code execution flaw in a web application, like yesterday's Drupal security vulnerability.

And yet people still

Meltdown
🕑Jan 15, 2018 🖋John Locke 💬0

Meltdown notes

The Meltdown vulnerability leaked out into public news a full week before patches were available for many distributions. When patches did become available, sometimes the patch caused further trouble.