Hackers are actively exploiting critical WordPress wp2shell vulnerabilities. Learn what businesses should do and how managed website monitoring can help.
A newly discovered set of critical WordPress vulnerabilities is already being used to compromise websites, install malicious software, and create hidden access points for attackers.
The vulnerabilities, collectively known as wp2shell, affect WordPress Core itself rather than a specific third-party plugin or theme. This makes the issue particularly important for businesses that rely on WordPress for their public website.
According to BleepingComputer, attackers are actively scanning the internet for vulnerable WordPress installations and using the flaws to install malicious plugins and persistent webshells. These webshells can provide continued access to a website even after the initial attack is complete.
What Is wp2shell?
Wp2shell is an attack chain involving two security vulnerabilities identified as CVE-2026-63030 and CVE-2026-60137.
When combined, the vulnerabilities may allow an attacker to execute commands on certain WordPress websites without first logging in. In other words, the attacker may not need a stolen password or an existing administrator account to begin compromising the site.
Security researchers have observed attackers using the vulnerability to:
- Install malicious WordPress plugins
- Place hidden PHP webshells on servers
- Collect administrator usernames and email addresses
- Attempt to access database credentials and authentication keys
- Gain access to WordPress administration panels
- Create unauthorized administrator accounts
- Maintain persistent remote access to compromised websites
Researchers have also reported widespread automated scanning, which means attackers are not necessarily targeting specific companies. They are searching for any vulnerable website they can find.
Which WordPress Versions Are Affected?
The complete remote code execution attack chain affects:
- WordPress 6.9.0 through 6.9.4
- WordPress 7.0.0 through 7.0.1
WordPress 6.8.0 through 6.8.5 is also affected by one of the underlying vulnerabilities.
WordPress has released patched versions, including WordPress 7.0.2, 6.9.5, and 6.8.6. The WordPress security team recommends updating affected websites immediately and has enabled forced automatic updates for supported installations because of the severity of the issue.
Website owners should not assume that an automatic update was completed successfully. Hosting limitations, file permissions, disabled automatic updates, incompatible plugins, or other technical issues can prevent an update from being applied.
Installing the Update May Not Be Enough
Updating WordPress is the most important first step, but it does not necessarily remove malicious files or accounts that were created before the update.
A website that was previously exposed should also be reviewed for signs of compromise, including:
- Recently installed or unfamiliar plugins
- Unexpected administrator accounts
- Modified WordPress files
- Unrecognized PHP files
- Changes within cache or upload directories
- Suspicious login activity
- Unexplained website redirects
- Performance problems or intermittent outages
- Unexpected changes to pages or search results
Logs should also be reviewed for activity associated with the vulnerable WordPress REST API endpoints. Security researchers recommend inspecting affected systems rather than relying on the update alone.
Your Website Is Part of Your Business Infrastructure
For many businesses, the company website is treated as a marketing project rather than an operational system. Once the site is launched, updates and maintenance may receive attention only when something stops working.
That approach creates unnecessary risk.
A compromised website can affect much more than its appearance. It can interrupt customer communications, damage search rankings, expose submitted information, redirect visitors to malicious pages, or harm the company’s reputation. A website outage can also prevent potential customers from finding contact information or learning about the company’s services.
Keeping a business website secure requires more than occasionally logging in and clicking an update button. It requires ongoing visibility into the health, availability, and security of the site.
How Recon Managed Services Can Help
Recon Managed Services offers solutions designed to help businesses keep their websites available, maintained, and better protected.
Depending on the needs of your website, our services can include:
- Website availability and uptime monitoring
- WordPress Core, plugin, and theme update management
- Security and malware monitoring
- Website backups and recovery planning
- Web application firewall and traffic protection
- SSL certificate and domain monitoring
- Performance and availability alerts
- Review of unexpected website changes
- Technical assistance when a website becomes unavailable or compromised
Instead of discovering a problem when a customer calls, proactive monitoring can provide earlier warning that a website is down, performing poorly, or showing signs of suspicious activity.
No security solution can eliminate every possible risk. However, proper maintenance, layered protection, reliable backups, and active monitoring can significantly reduce exposure and improve the ability to recover when something goes wrong.
Do Not Wait for Your Website to Become a Problem
The wp2shell vulnerabilities are an important reminder that even a well-designed website can become vulnerable when critical security updates are not identified and applied quickly.
Businesses should confirm that their WordPress installation has been updated to a patched version and review the website for any signs of unauthorized access. Organizations without a defined website maintenance and monitoring process should also consider who is responsible for identifying the next critical vulnerability.
Recon Managed Services can help monitor, maintain, and protect your company’s website so you can stay focused on running your business. Contact our team to discuss website monitoring and managed security options for your organization.






