Use cases
Software Products E-commerce MSPs Schools Development & Marketing DevOps Agencies Help Desk
Company
Internet Status Blog Pricing Log in Get started free

Outage in Liquid Web

Security Advisory: Critical WordPress Vulnerability - "Click2Shell"

Minor
September 22, 2026 - Started 1 day ago
Official incident page

Incident Report

WordPress has identified a critical security vulnerability designated as "Click2Shell" affecting all WordPress versions prior to 7.1.1. This vulnerability can enable unauthenticated Remote Code Execution (RCE) when a logged-in administrator visits a specially crafted link. Current Status & Hosting Actions Our engineering team is currently assessing our entire hosting fleet and determining next steps. There are currently no known workarounds for this vulnerability other than upgrading to the latest version of WordPress. Recommended Action for Customers We strongly advise all customers managing WordPress installations to review their environments immediately and update to WordPress version 7.1.1. We will continue to monitor the situation closely and provide further updates as new information becomes available.

Trusted by 1,000+ teams

The Status Page Aggregator with Early Outage Detection

Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.

IsDown status aggregator dashboard
Latest Updates ( sorted recent to last )
IDENTIFIED about 16 hours ago - at 09/23/2026 06:36AM

Our Engineering team continues to assess and work on the WordPress security vulnerabilities across our hosting fleet.

A new critical vulnerability, CVE-2026-87902, has been disclosed. WordPress 7.1.2 includes the security fix for this vulnerability.

Recommended Action for Customers

We strongly advise all customers managing WordPress installations to update to WordPress version 7.1.2 immediately.

We will continue to monitor the situation closely and provide further updates as new information becomes available.

INVESTIGATING 1 day ago - at 09/22/2026 08:13PM

WordPress has identified a critical security vulnerability designated as "Click2Shell" affecting all WordPress versions prior to 7.1.1. This vulnerability can enable unauthenticated Remote Code Execution (RCE) when a logged-in administrator visits a specially crafted link.
Current Status & Hosting Actions

Our engineering team is currently assessing our entire hosting fleet and determining next steps.

There are currently no known workarounds for this vulnerability other than upgrading to the latest version of WordPress.

Recommended Action for Customers

We strongly advise all customers managing WordPress installations to review their environments immediately and update to WordPress version 7.1.1.

We will continue to monitor the situation closely and provide further updates as new information becomes available.

The Status Page Aggregator with Early Outage Detection

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 6320 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook