Wire · regulatory
New wp2shell RCE Vulnerability Hits Millions of WordPress Sites, Emergency Patch Released
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 18 July 2026 · Fusion42 review
A critical unauthenticated remote code execution vulnerability (wp2shell) affecting WordPress Core 6.9.0-7.0.1 puts 500m+ sites at risk; emergency patches released as 7.0.2, 6.9.5, and 6.8.6.
This Wire brief sits within Fusion42's coverage of Cybersecurity.
◆ ◆ The Wire takeaway
If your product sits on WordPress or sells to WordPress agencies, your entire customer base is now a target for unauthenticated takeover until they patch to 7.0.2 or 6.9.5. You have a narrow window to force updates across your customer fleet before active exploitation starts.
◆ Coverage
1 source · 18 Jul 2026
◆ Related on Wire
◆ Topics