[List] Emergency Patch Released for Wordpress websites wp2shell Vulnerability.
John Gathii
jgathii at kictanet.or.ke
Mon Jul 20 12:22:03 EAT 2026
Dear listers,
We want to share a quick, practical update on a WordPress vulnerability
(wp2shell
) that may affect organisations running WordPress websites:
*What is “wp2shell”?*
wp2shell is a “no-login” Remote Code Execution (RCE) vulnerability in
WordPress core.
In simple terms, an attacker can target a vulnerable WordPress site from
the internet without needing to log in,and in the worst case may be able to
run code on the server. This can lead to site defacement, unauthorised
changes, and potential compromise of organisational information and
integrity, something particularly serious for human rights defenders and
social justice groups.
*Is your site affected?*
It affects specific WordPress versions:
WordPress 6.9.0 – 6.9.4 (fixed in 6.9.5)
WordPress 7.0.0 – 7.0.1 (fixed in 7.0.2)
If your site is not on those version ranges, you may not be affected but
please confirm your exact WordPress version.
*How to mitigate (what to do now)*
1) Upgrade WordPress immediately (best/complete fix)
Update to 7.0.2 depending on your current version.
After updating, verify the new version is actually running
2) Check for signs of compromise After updating/containment, quickly review:
any unexpected changes to admin users or roles
any new plugins/themes you didn’t install
unusual error logs or bursts of traffic endpoints
For any technical help please email us using help at tatua.digital or send us
a ticket by accessing our helpdesk portal : helpdesk.tatua.digital
--
With Kind Regards ,
*John Gathii*
Digital Resilience Fellow
Tatua Digital Resilience Centre <https://tatua.digital/about-us/>
@KICTANet <https://www.kictanet.or.ke/>
LinkedIn: John Gathii <https://www.linkedin.com/in/john-gathii/>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://tatua.digital/pipermail/list_tatua.digital/attachments/20260720/9e65d78d/attachment.html>
More information about the List
mailing list