Use cases
Software Products E-commerce MSPs Schools Development & Marketing DevOps Agencies Help Desk
Company
Internet Status Blog Pricing Log in Get started free

Outage in Liquid Web

WP2Shell Wordpress Core Critical Remote Code Execution Vulnerabilities, CVE-2026-60137 and CVE-2026-63030

Resolved Major
July 18, 2026 - Started 21 days ago - Lasted 6 days
Official incident page

Incident Report

Summary AI Generated

On July 17, 2026, WordPress.org disclosed two critical remote code execution vulnerabilities (CVE-2026-60137 and CVE-2026-63030), known as WP2Shell, affecting WordPress Core versions 6.8.x, 6.9.x, 7.0.x, and 7.1 beta, allowing unauthenticated attackers to execute arbitrary code on affected sites. Liquid Web engineers proactively upgraded affected WordPress installations across their fleet while continuing to advise customers to manually update to the patched versions. The incident spanned approximately 138 hours before being resolved on July 23, 2026.

On July 17th Wordpress.org announced two critical remote code execution (RCE) vulnerabilities commonly known as WP2Shell. These vulnerabilities exist in Wordpress Core and allow an unauthenticated request to execute arbitrary code on the target website. Customers running the Wordpress versions below are strongly advised to upgrade to latest version shown as soon as possible: Wordpress 6.8.x; fixed in 6.8.6 WordPress 6.9.x; fixed in 6.9.5 WordPress 7.0.x; fixed in 7.0.2 WordPress 7.1 beta, fixed in 7.1 beta2 Source: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/ Posted 2 minutes ago. Jul 17, 2026 - 21:44 EDT

Trusted by 1,000+ teams

The Status Page Aggregator with Early Outage Detection

Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.

IsDown status aggregator dashboard
Latest Updates ( sorted recent to last )
RESOLVED 15 days ago - at 07/23/2026 07:47PM

This incident has been resolved.

IDENTIFIED 18 days ago - at 07/20/2026 08:20PM

Given the severity of this vulnerability, Liquid Web Systems Engineers have been proactively upgrading affected Wordpress applications across our fleet. Customers are still strongly encouraged to review their Wordpress websites and, if affected, to update to the patched version as soon as possible.

IDENTIFIED 18 days ago - at 07/20/2026 11:48AM

We are continuing to work on a fix for this issue.

IDENTIFIED 18 days ago - at 07/20/2026 11:47AM

The issue has been identified and a fix is being implemented.

MONITORING 18 days ago - at 07/20/2026 11:43AM

Services have been restored, and websites are currently loading as expected. Our Network team is continuing to investigate the underlying cause and is actively monitoring the environment to ensure stability.

At this time, all services appear to be operating normally. If you experience any issues or need assistance, please contact our Support team.

IDENTIFIED 20 days ago - at 07/18/2026 11:15PM

Our teams continue to work diligently to assess the impact of the recently disclosed WordPress Core vulnerabilities and verify that appropriate mitigation measures are in place. We remain actively engaged in our investigation and are monitoring the situation for any new developments.

We will continue to closely monitor the situation and take any additional steps necessary to maintain system security and stability. If you need assistance or have any concerns, please contact our Support team.

INVESTIGATING 21 days ago - at 07/18/2026 01:48AM

On July 17th Wordpress.org announced two critical remote code execution (RCE) vulnerabilities commonly known as WP2Shell. These vulnerabilities exist in Wordpress Core and allow an unauthenticated request to execute arbitrary code on the target website.

Customers running the Wordpress versions below are strongly advised to upgrade to latest version shown as soon as possible:

Wordpress 6.8.x; fixed in 6.8.6
WordPress 6.9.x; fixed in 6.9.5
WordPress 7.0.x; fixed in 7.0.2
WordPress 7.1 beta, fixed in 7.1 beta2

Source: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
Posted 2 minutes ago. Jul 17, 2026 - 21:44 EDT

The Status Page Aggregator with Early Outage Detection

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 6320 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook