A WordPress website can continue to function perfectly on the front end whilst a security risk develops behind the scenes. In the case of wp2shell, the problem did not lie in a single plug-in, but in WordPress Core, the core software on which a WordPress website runs.
What is the wp2shell vulnerability?
Wp2shell is the name given to a combination of two vulnerabilities in certain versions of WordPress. By exploiting these vulnerabilities in combination, an attacker could potentially execute commands on affected installations without first logging in. This is known as remote code execution: executing code remotely on the server hosting the website.
An attack could result in modified files, an unknown administrator or malicious software. The full attack chain affected WordPress versions 6.9.0 to 6.9.4 inclusive and WordPress versions 7.0.0 to 7.0.1 inclusive. The 6.8 series was only affected by one of the two separate vulnerabilities.
On 17 July 2026, WordPress released official security updates in versions 6.8.6, 6.9.5 and 7.0.2. According to WordPress, versions prior to 6.8 were not affected by these specific issues. As of 27 July 2026, WordPress 7.0.2 was the latest official version.
Why it’s important to update WordPress promptly
As soon as a security vulnerability is made public, attackers can automatically scan for websites that have not yet been updated.
WordPress Core, plugins and themes together form a single technical environment. Each component must be checked and updated regularly. An outdated plugin can pose a risk, and wp2shell demonstrates that even the core software itself can contain a vulnerability.
Automatic updates can help, but it’s best to check whether the update has actually been carried out and whether the website is working correctly afterwards. This is particularly important for online shops, booking systems, forms and bespoke websites.
An update on its own is not always enough
A security update patches a known vulnerability. However, it does not automatically remove files, users or backdoors that were installed prior to the update. A backdoor is a hidden point of access that allows an attacker to return at a later date.
If your website was vulnerable during the active attack phase, it is advisable to carry out an additional WordPress security scan. This involves checking, amongst other things, files, users, plugins, the database and any available log files. SANS advised that a vulnerable installation should be regarded as potentially compromised and investigated further.
Important
An updated website is not automatically a verified website. Updating and verifying are two separate steps.
Monitoring helps to identify hidden problems more quickly
Many attacks do not immediately alter the visible pages. Your website may appear to be functioning normally whilst something unusual is happening in the background. WordPress monitoring helps you spot anomalies more quickly, such as:
- unexpected changes to files;
- unknown administrators;
- suspicious login attempts;
- malware or unwanted code;
- abnormal traffic or server usage.
Monitoring cannot prevent every incident. However, it does increase the likelihood that suspicious activity will be detected and investigated more quickly.
WordPress security consists of multiple layers
Keeping a WordPress website secure involves more than just clicking the update button every now and then. Effective WordPress security combines updates with secure backups, strong passwords, multi-factor authentication and restricted administrator rights. The number of active plugins also plays a part: find out why having too many WordPress plugins poses risks to your platform.
Malware scans, change monitoring and a properly configured firewall are also important. A Web Application Firewall, or WAF for short, checks internet traffic before it reaches the website.
Cloudflare has rolled out specific WAF security rules to block attacks exploiting these WordPress vulnerabilities. At the same time, Cloudflare emphasises that such a security layer is no substitute for the official WordPress update. Furthermore, the configuration and active security rules must be checked thoroughly.
How LOFT 33 can help secure your WordPress website
As a business owner, you don’t need to keep track of every new WordPress vulnerability yourself. LOFT 33 can update WordPress Core, plugins and themes in a controlled manner and check that key functions continue to work correctly after an update. This forms part of LOFT 33’s broader approach to websites and online shops.
In addition, we can provide secure backups, carry out malware and security checks, monitor suspicious changes and correctly configure Cloudflare or other firewall rules.
When a security alert is triggered, we first check which version and configuration your website is using. We then determine which updates, checks or additional measures are required. This means your website won’t receive a one-size-fits-all solution, but an approach tailored to its technology, features and risks. Book a no-obligation consultation if you’d like to find out where your website stands today.
Keep your WordPress website up to date and under supervision
Wp2shell demonstrates just how quickly a security vulnerability can become a practical risk. Updating WordPress regularly reduces the period during which a known vulnerability can be exploited. Monitoring helps you spot suspicious changes more quickly, even when the website continues to function normally on the front end.
Do you want to be sure that your WordPress website is up to date and being professionally managed? LOFT 33 can check your website, carry out technical maintenance and monitor it for potential security issues. That way, you don’t have to keep track of every new vulnerability or update yourself.
Please contact LOFT 33 for a no-obligation assessment or an introductory meeting.
Frequently Asked Questions about WordPress Security
Wp2shell is a combination of two security flaws in certain versions of WordPress Core. By exploiting these flaws in combination, an attacker could potentially execute commands without first logging in. WordPress has released security updates to address the vulnerabilities. Not every WordPress website was affected.
You can usually find the current version number in the WordPress dashboard under ‘Updates’. You should also check the versions of your plugins and themes. Don’t just check whether automatic updates are enabled; make sure they have actually been carried out. If you have a business website, it’s best to check that everything is working correctly after the update.
An update patches known security vulnerabilities, but does not automatically remove malware, unknown users or hidden backdoors that were previously installed. If your website was vulnerable during an active attack, a further check may be necessary. WordPress security therefore requires updates as well as backups, monitoring and regular technical checks.
Monitoring helps to identify suspicious changes more quickly. Examples include modified files, unknown administrators, unusual login attempts or unexpected server usage. Such issues are not always visible on the public website. Monitoring does not prevent every attack, but it helps to detect and investigate potential incidents more quickly.
LOFT 33 can carry out controlled updates to WordPress Core, plugins and themes. We can also handle backups, malware scans, security monitoring and Cloudflare configuration. In the event of a security alert, we first assess which risks are relevant to your website. We then advise on the updates, checks and additional security measures required.
You cannot know for certain without carrying out a check. An update patches the vulnerability, but does not reveal whether it had already been exploited. A security scan of files, users and log files will provide a definitive answer. If you are unsure whether your website was online during the period when it was vulnerable, have a check carried out before proceeding.
The cost depends on the size of the website, the number of plug-ins and whether there is already a suspicion that the site has been compromised. A one-off check is sometimes sufficient, whilst in other cases ongoing monitoring is recommended. LOFT 33 first assesses which situation applies and then proposes an appropriate approach.

