A critical wordpress vulnerability patch is now required for versions 6.9 through 7.0.1 due to the wp2shell flaw, which allows attackers to execute code on your site without any login credentials. WordPress released automatic updates to version 6.9.5 or 7.0.2, but you must verify your site updated successfully since over 500 million WordPress sites globally are exposed to this attack.
First, WordPress users face a critical emergency. A flaw called wp2shell in WordPress Core lets attackers run code on your site without any login, even a bare install with zero plugins is vulnerable. Versions 6.9 through 7.0.1 are affected. WordPress pushed automatic updates to version 6.9.5 or 7.0.2, but verify yours updated, this affects over 500 million sites globally.
Next, Microsoft warns of a surge in ACR Stealer malware attacks stealing browser passwords, authentication tokens, and sensitive documents from enterprise customers. This highlights why basic browser security matters.
And Ernst & Young disclosed a breach after hackers accessed their third-party IT support system containing client tax documents. This reminds us that your vendors' security is your security, always ask partners about their data protection.
Finally, hackers can exploit period tracking apps to spy on you according to WIRED, and Russian cyber spies are turning to infrastructure hacking. The lesson? Every connected system in your business is a potential entry point. Patch immediately, use multi-factor authentication, and review your vendor security practices.
Why this wordpress vulnerability patch matters to your small business
The wp2shell flaw in WordPress Core is a remote code execution vulnerability that bypasses authentication entirely. Even a bare WordPress install with no plugins is vulnerable. Attackers can inject malicious code, steal customer data, redirect traffic, or install ransomware. For professional services and manufacturing firms relying on WordPress for client portals or inventory management, this exposure directly threatens downtime and liability. The immediate action: Check your WordPress version (Dashboard > Updates) and confirm you are on 6.9.5 or 7.0.2 or later. Enable automatic updates in wp-config.php. If you cannot access your site, contact your hosting provider immediately. CISA and WordPress.org both flagged this as critical. Do not delay.
Key takeaways
- WordPress versions 6.9 through 7.0.1 are vulnerable to remote code execution via wp2shell flaw. Update to 6.9.5 or 7.0.2 immediately.
- Even WordPress sites with zero plugins are at risk. Attackers need no login credentials to exploit this vulnerability.
- Verify your update completed by checking Dashboard > Updates. If stuck on an older version, contact your hosting provider within 24 hours.
- Combine the patch with multi-factor authentication and a Web Application Firewall (WAF) to block additional attack vectors.
Frequently asked questions
How do I know if my WordPress site is vulnerable?
Log into your WordPress dashboard and go to Dashboard > Updates. If you see a pending update to version 6.9.5 or 7.0.2, your site is still vulnerable. If the dashboard shows your site is fully updated, the patch has been applied. If you cannot access your dashboard, contact your hosting provider immediately.
What can attackers do if they exploit wp2shell on my site?
Attackers can run any code on your server without authentication, meaning they can steal customer data, plant ransomware, redirect visitors to malicious sites, or take your site offline entirely. This directly impacts uptime and customer trust.
Should I turn off automatic updates for WordPress?
No. Automatic updates are your fastest defense against critical flaws like wp2shell. Enable them by adding define('AUTOMATIC_UPDATER_DISABLED', false); to wp-config.php. Manual patching is slower and often missed by small teams.
What if my hosting provider hasn't updated my WordPress yet?
Contact them immediately and escalate to their security team. Request a manual update to WordPress 6.9.5 or 7.0.2. If they delay beyond 48 hours, consider switching hosts or hiring a WordPress security consultant to patch it yourself.
Sources
- https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html
- https://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-acr-stealer-attacks-on-customers/
- https://securityaffairs.com/195550/data-breach/ernst-young-ey-investigates-data-breach-involving-third-party-support-tickets.html
- https://www.wired.com/story/security-news-this-week-your-period-tracker-is-probably-spying-on-you/