← Back

Wire · regulatory

New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released

Published

18 July 2026

Topic

regulatory

Sectors

Cybersecurity

Source

Read at cybersecuritynews.com

Verified

Fusion42 · 18 July 2026 · Fusion42 review

A critical unauthenticated remote code execution vulnerability (wp2shell) affecting WordPress Core 6.9.0-7.0.1 puts 500m+ sites at risk; emergency patches released as 7.0.2, 6.9.5, and 6.8.6.

This Wire brief sits within Fusion42's coverage of Cybersecurity.

◆ The Wire takeaway

If your product sits on WordPress or sells to WordPress agencies, your entire customer base is now a target for unauthenticated takeover until they patch to 7.0.2 or 6.9.5. You have a narrow window to force updates across your customer fleet before active exploitation starts.

Coverage

1 source · 18 Jul 2026

Related on Wire

Topics

Cybersecuritywordpress-securityrce-vulnerabilitycve-2026-63030saas-riskemergency-patch