Updated on 30 Jul 2026
A security vulnerability in WordPress Core – known as wp2shell – was publicly disclosed on 17th July 2026. If you're running a WordPress site, it's worth taking a few minutes to understand the key facts and protect your site.
What is it?
wp2shell (CVE-2026-63030) is a flaw in WordPress Core that could allow an unauthorised attacker to run code on your site remotely. Public exploit code has been circulating since the disclosure date, so it's important to make sure your site is updated to a patched version immediately.
Is your site vulnerable?
Check your WordPress version in the "At a Glance" panel on your admin dashboard. Here's what you need to know:
If you're unsure, Searchlight Cyber – the team that discovered the vulnerability – offers a free checker at wp2shell.com.
What should you do?
- Restore a backup of your site – if you have a backup of your site taken before 17th July 2026, restoring that backup gives you the most confidence your site is not impacted by this vulnerability. Keep in mind that restoring a backup may mean any content you've added since that backup was taken is lost or overwritten
- Update WordPress – if you're on an affected version, head to Dashboard > Updates and install the latest release. This is the most important step.
- Check your site if you were on an affected version – updating closes the vulnerability, but if your site has already been impacted, there are additional steps you should take. You should check your WordPress site for any new unexpected users and plugins – if you find any, remove them immediately.
- Reset your credentials – as a precaution, change your Fasthosts Control Panel password and any email account passwords associated with your site. If you use payment gateways, API keys, or other third-party services, it's worth regenerating those from within each provider's dashboard too.
If you need a hand with any of this, our support team is available 24/7. You can also find a full breakdown of how to protect and recover your WordPress site in this article.