Back to blogSecurity Alerts

Wp2shell WordPress Core Hack Explained for Busy Site Owners

||7 min read
Share
Blue WordPress logo on a dark screen with glowing green code and a red warning triangle in the foreground

Upgrade Your WordPress Support Today

Join hundreds of satisfied customers who trust our personalized WordPress hosting and maintenance plans and SEO/GEO Services. Keep your site secure, fast.

WordPress Care Plans And SEO/GEO Services

Why WP2Shell Matters For Your Small Business Website: A serious WordPress core hack called WP2Shell is giving attackers a shortcut straight into business websites, even when passwords are strong and plugins look fine. For a small business, that can mean online orders stopping without warning, customers seeing scam pages instead of your content, or you being locked out of your own dashboard. Lost sales, damaged trust, and a long list of clean-up tasks often follow.

In this article, we explain what WP2Shell actually is in plain language, how to tell if your site is at risk, and simple steps you can take today to secure it. You do not need to be technical to protect your business. A few clear actions, and a bit of ongoing WordPress help when you need it, go a long way.

As a Canadian WordPress support partner, we at WP Lifeline watch these threats closely so small business owners without in-house IT can still stay ahead of them.

What the WP2Shell Vulnerability Actually Does

WP2Shell is not a single bug; it is a chain of two weaknesses inside WordPress core that attackers can link together to take over a site without logging in.

First, there is an SQL injection issue, listed as CVE-2026-60137. In simple terms, this means attackers can slip harmful commands into the WordPress database when the site does not expect it. They do not need an account to try this. If it works, they gain a way to run instructions that WordPress was never meant to follow.

The second piece is a flaw in the WordPress REST API batch feature, listed as CVE-2026-63030. The batch feature is meant to let WordPress handle several API requests at once. With this vulnerability, it can get confused about which routes or paths are allowed, and hackers can use that confusion to run powerful actions they should not have access to.

When those two problems are combined, attackers can reach what is called remote code execution. In everyday language, that means they can make your site run their code from a distance, without logging in and without knowing any passwords.

Versions 6.9 through 6.9.4 and 7.0 through 7.0.1 of WordPress core are affected. If your site is on one of those versions, it is a potential target.

Once a hacker gets in through WP2Shell, they can create their own administrator accounts and lock you out, upload hidden files that keep the door open even after an update, inject spam pages or malware that infect visitors, or redirect traffic to fake login pages, fake shops, or scam sites.

This is not a plugin or theme issue. It lives inside WordPress core itself, so every site on those versions is exposed, no matter which design or plugins you use.

How to Quickly Check If Your WordPress Site Is At Risk

The first step is simply to find out which WordPress version you are running. Log into your dashboard as usual. You can usually see the version number in the bottom right corner of the admin screen in the grey footer, or in the At a Glance widget on the main Dashboard screen.

Compare that number with the vulnerable ranges: if you see anything from 6.9 to 6.9.4, or 7.0 to 7.0.1, your site needs attention. If your version is lower than 6.9, you still need to update, because older versions miss many other security fixes, even if WP2Shell specifics do not apply.

Here's the breakdown:

WordPress 6.9 is affected by both vulnerabilities.

Version 6.9.5 has been released containing fixes for both.

WordPress 6.8 is only affected by the first vulnerability.

Version 6.8.6 has been released containing a fix.

The beta release of WordPress 7.1 is affected by both vulnerabilities.

Version 7.1 beta2 has been released containing fixes for both.

Versions of WordPress prior to 6.8 are not affected.

Even with the right version, it pays to watch for warning signs that something is not right.

  • Unfamiliar administrator accounts under Users.
  • Strange plugins or themes that you do not remember installing, or plugins vanishing for no clear reason.
  • Sudden changes in site behaviour, such as random redirects or new pop-ups.

A simple routine helps: log into your dashboard at least once a week, glance at the Users list, and check if any updates are waiting. If anything feels off, it is better to assume the site needs a closer look than to hope it will sort itself out. This is exactly the moment where professional WordPress help can save you time and stress.

Step-by-Step: Updating WordPress To A Safe Version

For WP2Shell, the most important fix is straightforward: update WordPress core to 6.9.5, 7.0.2, or any newer version available. These releases contain patches for the two vulnerabilities in the chain.

Here is a non-technical way to do it safely.

  1. Back up your site

Use your hosting control panel or your usual backup plugin to take a full backup of both files and the database. If your host offers one-click backups, trigger one before you change anything.

  1. Log in as an administrator

Sign in with an admin account, then go to Dashboard, then Updates.

  1. Run the update

If you see a message that a new version of WordPress is available, click Update Now. Wait until WordPress confirms that the update is complete. Do not close the browser tab while it is running.

  1. Check the site

Visit the public side of your site in another tab to make sure pages are loading and basic features work.

If the newest version does not appear as an option, automatic updates may be turned off or your hosting environment might be holding things back. In that case, you can enable automatic updates in the same Updates screen or ask your host to allow current versions.

Most sites update without drama. If something does break, this is where your fresh backup earns its keep. You can restore it or get WordPress help rather than trying risky fixes from random forum posts.

Simple Checks To Spot Hackers And Hidden Backdoors

Once you are on a patched version, you still want to make sure no one slipped in before you updated.

Start with your user accounts. From the dashboard, go to Users, then All Users. Slowly scan the list of administrators. If you see names or email addresses you do not recognize, especially generic ones, check with your team. If no one claims them, downgrade them to a lower role or remove them.

Next, take a look at plugins and files. From Plugins, Installed Plugins, see if anything looks odd, such as strangely named plugins or tools that do not match your usual setup.

In your hosting control panel, many providers have a file manager that lets you view the wp-content folder. Red flags include: new folders with random names or long strings of letters and numbers; files that appeared or changed very recently when no updates were done; or multiple copies of the same plugin with slightly different names.

A security plugin can help scan for known malware patterns, though it is still worth combining that with human review.

Building a More Resilient WordPress Site Going Forward

WP2Shell is a good reminder that security is not something you fix once and forget. Fortunately, non-technical owners can follow a simple routine that lowers risk a lot.

Keep WordPress core, themes, and plugins updated. Remove add-ons you no longer use instead of leaving them installed and inactive. Use strong, unique passwords, and turn on two-factor authentication for administrator accounts where possible so a stolen password is not enough for access.

Security also connects directly to SEO and visibility. When a site is hacked or filled with spam content, search engines are more likely to reduce its rankings or show warnings. That means fewer visitors, fewer leads, and recovery that can take time even after the technical issue is fixed.

For a small business, that drop in visibility can be as painful as the security breach itself.

Ongoing professional WordPress help can take the pressure off you to watch every update or security notice on your own. With a trusted partner keeping an eye on maintenance, security, and SEO health, you can spend more energy on running your business, knowing someone else is watching the technical side that keeps your site visible and safe.

If you want expert support improving your search visibility while keeping your site secure, explore our SEO plans.

Get Started With Your Project Today

If you are ready to improve your site's performance and visibility, our team is here to provide expert WordPress help tailored to your goals. At WP Lifeline, we work with you to identify what your website really needs so every change has a clear purpose. Reach out to contact us and we will walk you through the next steps so you can move forward with confidence.

Frequently Asked Questions

What is the WP2Shell WordPress core hack?

WP2Shell is a chain of two security weaknesses in WordPress core that can be combined to take over a site without logging in. It can lead to remote code execution, meaning attackers can run their own code on your site from a distance.

Which WordPress versions are vulnerable to WP2Shell?

WordPress core versions 6.9 through 6.9.4 and 7.0 through 7.0.1 are vulnerable. WordPress 6.9.5 and later include fixes, and WordPress 6.8.6 fixes the SQL injection issue affecting 6.8.

How do I check if my WordPress site is at risk for WP2Shell?

Log into your WordPress dashboard and look for the version number in the admin footer or the At a Glance box on the Dashboard screen. If it is in the ranges 6.9 to 6.9.4 or 7.0 to 7.0.1, update immediately to a fixed version.

Is WP2Shell caused by a plugin or theme, or WordPress core?

WP2Shell is a WordPress core issue, not a plugin or theme problem. That means any site running the vulnerable core versions can be exposed even if all plugins and themes look normal.

What are the warning signs that my WordPress site might be compromised by WP2Shell?

Common signs include unfamiliar administrator accounts, plugins or themes you did not install, or sudden changes like redirects and unexpected content. A hacked site may also show scam pages, inject spam, or lock you out of the dashboard.