WordPress 7.0.2 – Update immediately. What Happened with the Recent wp2shell Vulnerability (and How to Stay Safe)
By: Bobby
Published on: Jul 20, 2026
< 1 min read.
If you run a WordPress website, you’ve probably seen the headlines. Just days ago, on July 17, 2026, WordPress pushed out emergency security updates for a critical vulnerability that left thousands of sites exposed.
What Was the Issue?
The vulnerability, dubbed wp2shell, is a chain of two flaws in WordPress core:
This allowed unauthenticated attackers to achieve remote code execution (RCE) on affected sites — no login required. It primarily impacted WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1. WordPress responded quickly with forced automatic updates to versions 7.0.2, 6.9.5, and 6.8.6.
We recently dealt with exactly this on a client site we host. The good news? We caught it fast (thank God for server backups), cleaned everything up, and got the site back to full security.
Moral of the story: Back everything up regularly, and keep every plugin and the core itself updated.
What Should You Do Right Now?
- Update immediately — Check that your site is running WordPress 7.0.2 or newer.
- Review plugins & themes — Remove anything unused. Update everything else.
- Strengthen security — Use a solid security plugin (like Wordfence), enable auto-updates where safe, and limit user permissions.
- Monitor logs — Watch for suspicious activity, especially around the REST API.
At Catchy Labs, we help Oklahoma and surrounding businesses keep their websites secure, fast, and performing at their best. From emergency cleanups to proactive maintenance and custom development, we’ve got your back.
Has your site been acting strangely lately? Contact us for a free security review. Don’t wait until the next vulnerability hits.