- another update massive amounts of cyber issues https://wordpress.org/documentation/wordpress-version/version-7-0-3/
the positive [+] always first: wordpress devs have managed to keep updates high quality (in 5 years time nothing was broken after update) this only can be acchieved with massive quality (use case) testing (writing a lot of tests, doing a lot of tests) amazingly good job, that is incredibly difficult for a software that complex, that is heavily modded by 3rd party plugins, themes, vendors
the ease of use and the amount of themes is what usually brings users to wordpress
the negative [-]: wordpress hosted or self hosted NEEDS a 100% reliable auto self update mechanism 😬🤔 if that is not given, all self hosted longterm wordpress installations are at risk (maybe that’s on purpose?) to be hacked long term 🙁 (also damaging wordpress reputation)
so if the web dev user wants a almost unhackable website… convert to static X-D
then it’s the webhosters task to keep apache2 + php (the LAMP stack) updated
the positive [+] https://www.hetzner.com/ is doing a great job as webhoster in many regards.
the negative [-] there is no option to “always use the latest version when it becomes available” (aka another auto update function missing 🙁 so the user has to manually check into konsoleh and select the latest php version when it becomes available, this is not sustainable, 90% of users will forget, exposing their websites to possibly to web based security risks or being abused as spam host.
… well this post has not aged well… because as the user might have realized or not dwaves.de was not available for a while X-D
wp2shell is exploiting wordpress CORE functionality to gain root access and drop a webshell that allows the attacker to do whatever the attacker wants on a user’s php (and usually apache2) powered webspace 🙁
so it does not matter how many or little plugins the user had installed… the exploit exploited wordpress core code. and: it’s fixed in 7.0.2, but the auto update mechanism of wordpress is not working well 🙁 and so the chance is high a lot of users are not updating on time 🙁
any internet connected software actually needs automatic hourly checks for updates
wordpress in 2026 A TON of websites are using wordpress, some say 40% of all websites
As of late July 2026, internet scans by Censys observed roughly 7.74 million version-visible WordPress instances globally in the vulnerable WP2Shell remote code execution range (versions 6.9.x and 7.0.x), out of roughly 62.8 million total observed instances and an estimated 500 million total sites worldwide. [1, 2]
Scope and Exposure Data
- Total WordPress Sites: Estimated at 500 million globally.
- Observed Active Instances: ~62.8 million instances detected via global scans.
- Vulnerable RCE Range (6.9.x / 7.0.x): ~7.74 million version-visible instances (~12% of observed total).
- Broader SQL Injection Range (including 6.8.x): ~8.60 million instances (~14% of observed total).
- Largest Single Cluster: WordPress 7.0.1 alone accounted for roughly 5.11 million instances.
- Visibility Caveat: Only about 25% of instances expose a version tag, meaning the true count of vulnerable installations is likely higher. [1, 2]
Vulnerability Overview
- Name: wp2shell (CVE-2026-63030 and CVE-2026-60137)
- Type: Unauthenticated Remote Code Execution (RCE) chain in WordPress Core
- Disclosed & Patched: July 17, 2026 (Fixed in versions 6.8.6, 6.9.5, and 7.0.2)
- Status: Added to the CISA KEV Catalog on July 21, 2026, with active in-the-wild exploitation and millions of blocked attack attempts recorded by security vendors like Wordfence. [1, 2, 3, 4, 5]
because in times of AI the time from exploit found to exploit exploited is in hours not days
- https://github.com/0xsha/wp2shell
- be careful to run anything from github or the internet in general 😀 it could be what it claims to be but it could also be a backdoor
liked this article?
- only together we can create a truly free world
- plz support dwaves to keep it up & running!
- (yes the info on the internet is (mostly) free but beer is still not free (still have to work on that))
- really really hate advertisement
- contribute: whenever a solution was found, blog about it for others to find!
- talk about, recommend & link to this blog and articles
- thanks to all who contribute!



