Important WordPress Security Update: WP2Shell Vulnerability

A serious security issue, known as WP2Shell, has been identified in WordPress core. It affects some recent WordPress versions and is being actively targeted, so affected websites should be checked and updated as a priority.

Unlike many WordPress security issues, this is not related to a particular plugin or theme. It is an issue in WordPress itself, meaning a website may be affected even if it has very few plugins installed.

Which websites are affected?

The WP2Shell issue affects:

The secure releases are:

  • WordPress 6.9.5
  • WordPress 7.0.2

WordPress 6.8 sites are not affected by this particular WP2Shell issue. However, they should still be kept up to date, as the related security release also addressed a separate vulnerability.

Why is this important?

If a vulnerable site is publicly accessible, an attacker may be able to exploit the issue without needing a WordPress login. In the most serious cases, this could allow changes to be made to the website or its data.

Security organisations have reported active exploitation since the update was released, so this should be treated as an urgent update rather than routine maintenance.

What should I do?

Check the WordPress version shown in your website dashboard. If it is an affected version, arrange for WordPress core to be updated as soon as possible.

After any urgent security update, it is sensible to check that the main parts of the website are working normally, including contact forms, online bookings, payments and any customer login areas.

If you have an O’Brien Media support agreement and sufficient support time available, we will handle appropriate WordPress security updates as part of your support, if you don’t have sufficient support time remaining we will contact you directly as a matter of urgency.

If you are unsure whether your website is affected, or would like us to check it, please contact our support team.

Last updated byChris Grant (he/him)Chris Grant (he/him)