At Tatua Digital Resilience Centre, our priority is keeping the tools that amplify and protect human rights defenders, journalists, and social justice groups secure and operational. Right now there is a critical threat that requires immediate action: the “wp2shell” vulnerability in WordPress core.

What is wp2shell and why it matters
The “wp2shell” flaw is a critical WordPress core Remote Code Execution (RCE) vulnerability. Unlike many common vulnerabilities, attackers can exploit this issue without logging in. That means a remote actor can run arbitrary code on your server quickly and quietly.
Why you should care
- Website takeover: attackers can deface pages or make unauthorized content changes.
- Data exposure: sensitive information about staff, partners, or the people you support can be leaked.
- Operational loss: an attacker can delete or lock you out of your site, disrupting communications and fundraising.
For organisations working with vulnerable populations, a compromised site can directly endanger people’s safety, confidentiality, and the organisation’s credibility.
Who is at risk
Any publicly accessible WordPress site running affected versions is at risk. Specifically check your site’s version and hosting environment:
- WordPress 6.9.0 through 6.9.4 (patched in 6.9.5)
- WordPress 7.0.0 through 7.0.1 (patched in 7.0.2)
If your version differs, confirm the exact version before assuming safety.
Immediate response – what to do now
Time matters. Follow these steps immediately:
- Update WordPress now. Upgrade to 6.9.5 or 7.0.2. If you don’t manage the site, contact your hosting provider or web manager and demand the update.
- Verify the patch. Check Dashboard – Updates or ask for written confirmation from your provider that the site is on a patched version.
- Conduct a post-update audit. Look for signs of compromise: unexpected administrator accounts, unknown plugins/themes, modified files, or visible content changes.
- If you use managed hosting with automatic updates, confirm the provider applied the correct patch and that automatic updates are functioning.
If you’ve been compromised – rapid recovery steps
If you find evidence of an active compromise, act decisively:
- Take the site offline to stop further damage and data loss.
- Restore from a known-clean backup created before the compromise.
- Apply the security patch (6.9.5 or 7.0.2) before bringing the site back online.
- Rotate all administrator and service account passwords; force password resets for users where appropriate.
- Scan files and logs to identify how the attacker entered and what they changed. Preserve logs for investigation and potential accountability.
- If you support vulnerable clients, inform them about potential exposure and take protective steps for affected individuals.
Long-term resilience – reduce future risk
Security is continuous. Strengthen your site with these measures:
- Enable two-factor authentication (2FA) for all administrator accounts.
- Keep WordPress core, plugins, and themes updated. Apply critical patches promptly.
- Maintain regular, offsite, versioned backups and test restores.
- Limit admin accounts; follow least-privilege principles.
- Use a web application firewall (WAF) or host-level protections to reduce exposure.
- Monitor site integrity and logs for suspicious changes and automate alerts where possible.
Need help?
If you’re unsure about your site’s status, need help updating, or suspect a compromise, contact your hosting provider immediately. Tatua Digital Resilience Centre is also available to assist organisations providing emergency technical support and incident response-reach out for guidance or escalation.
Our digital presence is often the first line of defence for the communities we serve. Act now to secure your site and protect the people who depend on it.To access technical support send an email to us : help@tatua.digital
Subscribe to the Tatua mailing list to receive updates, announcements, and important information directly in your inbox. Join here: tatua.digital mailing list.