What is WP2Shell?
WP2Shell is the name given to a pair of vulnerabilities found in WordPress core itself. Not a theme, not a plugin, but the base software that every single WordPress website runs on. When chained together, these two flaws let an attacker take complete control of a website with no login, no user interaction, and no vulnerable plugin required.
Why is this one different from a typical plugin hack
Most WordPress hacks in recent years have come through an outdated plugin or a poorly coded theme. WP2Shell is different. It reaches straight into a standard, stock WordPress installation. If your site is running an affected version, it is exposed, regardless of how careful you have been with your plugins and themes.
Why the risk is so widespread
WordPress powers a huge proportion of the websites on the internet, which means the number of potentially vulnerable sites runs into the hundreds of millions. Public proof of concept code for the exploit appeared within days of the vulnerability being disclosed, and cyber security researchers confirmed attackers were actively exploiting it almost immediately afterwards. This was never a theoretical risk. It was, and in many cases still is, a live and active threat sitting on an enormous number of live websites.
Is your website affected?
WP2Shell only affects certain versions of WordPress, so the first thing to do is find out exactly which version your website is currently running. If you fall into the affected range below, your site is potentially exposed and should be updated as a priority.
WordPress Versions at risk:
- WordPress 6.9.0 through to 6.9.4
- WordPress 7.0.0 through to 7.0.1
WordPress Versions with the fix applied:
- WordPress 6.9.5
- WordPress 7.0.2
- WordPress 6.8.6 (backported fix for older installations)
How to check your WordPress version
Log in to your WordPress dashboard and look at the main overview page, where your current version is usually displayed. If you are not confident finding this yourself, ask whoever manages your site, or get in touch with us and we can check it for you.

What it means if you cannot update
If you find you are on an affected version and the update option is greyed out, missing, or simply will not apply, this is a strong sign that your site has already been hacked. Attackers exploiting WP2Shell can deliberately block WordPress from updating itself, keeping the site on a vulnerable version so they can retain access without ever needing a password. If you see this happening, treat it as urgent and get the site checked immediately.
If you are not sure whether your website falls into this situation, we can take a look for you. We already prevent exactly this kind of thing happening across the 100+ websites we manage, through regular WordPress maintenance that keeps every site updated, monitored, and secure before problems like this can take hold.

What’s at stake if your site is compromised
If an attacker gains access to your website through WP2Shell, the consequences go well beyond a defaced homepage. A compromised site can be used quietly in the background for weeks without you noticing, while doing real damage to your business and your visitors.
- Stolen passwords and credentials: Administrator logins and other stored data can be extracted directly from your database
- Hidden malware: Malicious code or plugins can be installed without any visible sign on the surface
- Altered or damaged content: Pages can be changed, defaced, or replaced entirely
- Your site used to attack others: A compromised website can be turned into a launchpad for further attacks, risking your reputation and potentially getting your domain blacklisted
The only real fix for WP2Shell
There is no clever workaround for WP2Shell. If a site has already been compromised, updating alone is not enough, any code or access the attacker has planted needs to be found and removed first, otherwise they can simply let themselves back in later. Once the site is clean, the priority is to force an update to a fixed version of WordPress.
Beyond that, ongoing updates and regular maintenance are what keep a website protected against the next vulnerability like WP2Shell, not just this one. WordPress has enabled forced automatic updates for supported installations because of how serious this issue is, but forced updates do not reach every site. Sites with auto-updates disabled, sites running older unsupported versions, and sites that have not been properly maintained can all be left exposed.
How Loose Connections protects its clients for WordPress security breaches
Our proactive maintenance approach
This is exactly the kind of situation that shows the value of proper, ongoing website maintenance. We manage and monitor over 100 client websites, and our structured maintenance process means core updates like this are identified and applied proactively, not weeks or months after the fact.
Our approach means:
- Core WordPress updates are applied promptly, as part of routine, scheduled maintenance
- Plugins and themes are kept current, reducing the number of ways a site can be exploited
- Security monitoring is in place to flag suspicious activity early
- Clients receive clear reporting, so they know their site is being looked after without needing to understand the technical detail themselves
When something like WP2Shell breaks, our clients do not need to scramble. Their sites are already being watched.
Why proactive beats reactive
Waiting until a website is hacked before dealing with security is always the more expensive and more stressful option. By that point, there is often lost content to recover, malware to remove, and customer trust to rebuild, on top of the original problem that could have been prevented with a routine update. Proactive maintenance catches issues like WP2Shell before they ever reach that stage, so a five minute update replaces what could otherwise be days of clean up and downtime.
Over 100 websites, kept running securely
We currently manage and maintain more than 100 client websites, each kept updated, monitored, and protected as part of our ongoing maintenance service. Our clients do not have to think about vulnerabilities like WP2Shell because their sites are already covered, running securely with minimal downtime, so they can focus on their business instead of worrying about their website.
Is your website exposed right now?
If you manage your own WordPress website, or you are not entirely sure who is keeping it updated, now is a good time to find out. WP2Shell is already being actively exploited, and the businesses most at risk are the ones who assume their website is fine simply because nothing has gone wrong yet.
If you would like Loose Connections to take that worry off your hands, in the same way we already do for more than 100 other businesses, we would be glad to help.
