A critical WordPress issue is being actively exploited
A serious WordPress core security issue, publicly known as WP2Shell, is being actively exploited. It combines two vulnerabilities, CVE-2026-60137 and CVE-2026-63030, in a way that can allow an attacker to take control of a vulnerable WordPress site without needing a login.
This is not a plugin issue. It is not tied to a specific theme. It is also not an issue with our hosting platform or servers. WP2Shell affects the WordPress application itself, which means vulnerable WordPress sites can be at risk regardless of where they are hosted.
Who is affected
The critical WP2Shell chain affects sites running:
- WordPress 6.9.0 to 6.9.4
- WordPress 7.0.0 to 7.0.1
Fixed versions have been released. Sites on the affected 6.9 branch should be updated to WordPress 6.9.5 or later. Sites on the affected 7.0 branch should be updated to WordPress 7.0.2 or later.
WordPress has enabled forced automatic updates for affected versions, but site owners should not assume the update completed successfully. Automatic updates can fail because of file permissions, hosting restrictions, disabled update settings, custom deployment processes, or other site-specific issues.
What ALPHA+V3 has done for maintenance clients
Clients on an active ALPHA+V3 WordPress maintenance plan are covered. We have handled the required WordPress core updates for maintained sites and are continuing to monitor for related issues.
That is exactly why ongoing WordPress maintenance matters. Security updates are not just routine housekeeping. When a vulnerability like this is disclosed, the response needs to be prompt, careful, and verified.
What unmanaged WordPress site owners should do now
If your WordPress site is not on a maintenance plan, check it immediately.
Start with the WordPress version number. In most cases, you can find this in the WordPress dashboard under Updates, or near the bottom of the admin area. If the site is running WordPress 6.9.0 to 6.9.4 or 7.0.0 to 7.0.1, it should be updated right away.
After updating, do a basic review for signs that something may have changed before the patch was applied:
- Review administrator accounts and remove anything unfamiliar.
- Check recently installed plugins and themes.
- Look for unexpected file changes.
- Review contact forms, redirects, and unusual site behaviour.
- Confirm that backups are current and restorable.
- Ask your host or maintenance provider to review logs if you suspect compromise.
If you are not comfortable checking this yourself, do not wait. Contact whoever manages your website and ask them to confirm the installed WordPress version and whether the site has been reviewed.
Hosting still matters, but this is a WordPress core issue
Good managed hosting can help with monitoring, backups, isolation, and recovery. It can also make emergency response easier. But hosting alone does not remove the need to maintain WordPress itself.
WP2Shell is a reminder that WordPress security is shared between the application, the hosting environment, and the people responsible for ongoing updates. A well-managed site is not just built once and left alone. It needs regular care, especially when critical security releases are issued.
If your site is not on a maintenance plan
If your WordPress site is important to your business, it should have a clear maintenance process. That includes core updates, plugin and theme updates, backups, monitoring, and a defined response when critical issues are disclosed.
A maintenance plan is not just about keeping things tidy. It reduces the chance that an urgent security issue gets missed, delayed, or handled without verification.
If you are unsure whether your WordPress site is affected by WP2Shell, ALPHA+V3 can review your site and help determine the right next step. Unmanaged WordPress site owners can also request help by emailing web@getalpha.ca to open a support ticket. Charges may apply.
If you need help confirming your WordPress version, reviewing your site, or setting up ongoing maintenance, ALPHA+V3 can help you decide what needs attention first.
Sources
- WordPress 7.0.2 Security Release
- WordPress GitHub Security Advisory for CVE-2026-63030
- Bitdefender WP2Shell Technical Advisory
- SecurityWeek report on active exploitation