WordPress Site Owners Urged to Install Emergency Security Update
A critical vulnerability chain affecting WordPress Core could allow attackers to take control of unpatched websites without logging in or exploiting a plugin.
WordPress has released an emergency security update addressing two serious vulnerabilities in its Core software, including a flaw that can lead to remote code execution.
The vulnerability chain, known as wp2shell, does not require an attacker to have an account or exploit a separate weakness in a plugin or theme.
WordPress 7.0.2 was released on July 17, 2026, with fixes for one critical and one high-severity security issue. Forced automatic updates were also enabled for affected installations.
The WordPress Security Alert Explained
Stay Updated on Gaming and Technology Security
Get security alerts, gaming news, reviews, interviews, and independent coverage from Fix Gaming Channel.
Join Our Newsletter
Stay updated with the latest interviews, previews, security reports, and indie gaming news.
What Is wp2shell?
wp2shell combines a SQL injection vulnerability with a separate flaw involving WordPress REST API batch requests.
When chained together, the vulnerabilities could allow an anonymous attacker to create an administrator account and execute code through the compromised website.
Because the flaw affects WordPress Core, a site does not need to be running a vulnerable plugin or theme for the full attack chain to work.
Which Versions Are Affected?
The complete remote-code-execution chain affects WordPress 6.9.0 through 6.9.4 and WordPress 7.0.0 through 7.0.1.
WordPress 6.8 is affected by the separate SQL injection issue but not the second vulnerability required for the complete attack chain.
The patched releases are WordPress 7.0.2, 6.9.5, and 6.8.6. Versions released before WordPress 6.8 are not affected by these particular vulnerabilities.
What Site Owners Should Do
Administrators should open Dashboard → Updates and confirm that their installation is running WordPress 7.0.2, 6.9.5, 6.8.6, or a newer stable release.
After updating, create a fresh backup, review administrator accounts and installed plugins, and run a security scan. A firewall may reduce the risk of exploitation, but it does not replace the official update.
Fix Gaming Channel has confirmed that its own website is now running WordPress 7.0.2.
Sources
WordPress 7.0.2 Security Release
Searchlight Cyber: wp2shell Security Advisory
Wordfence: wp2shell Exploitation Activity
Related Reading
YouTube Channel Hacked: My Story and Cybersecurity Wake-Up Call
Steam and Discord Scams Are Getting Smarter in 2026
More Gaming Security and Cybercrime Coverage
Written by Ronny Fiksdahl, Founder & Editor of Fix Gaming Channel.
Send interview pitches, corrections, tips, or developer stories to contact@fixgamingchannel.com.
Support independent games coverage on Ko-fi.
