## Incident Summary On July 17, 2026, WordPress.org disclosed two critical remote code execution vulnerabilities (CVE-2026-60137 and CVE-2026-63030), known as WP2Shell, affecting WordPress Core versions 6.8.x, 6.9.x, 7.0.x, and 7.1 beta — allowing unauthenticated attackers to execute arbitrary code on affected sites. Nexcess engineers proactively applied WordPress Core updates across the Managed WordPress platform, and deployed a must-use plugin as a mitigation for sites that could not be automatically updated. The incident was fully resolved on July 23, 2026, after approximately 138 hours, with all customers advised to confirm their sites are running the latest patched WordPress version.
Trusted by 1,000+ teams
Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.
This incident has been resolved.
The Nexcess Managed Wordpress platform configures Wordpress Core updates by default and the vast majority of websites have been updated. Nexcess System Engineers proactively attempted to update affected websites that were not already on the patched version. In some cases this was not possible to do. The Nexcess Managed Wordpress Development team has pushed a must-use plugin that mitigates this vulnerability where the application is not on a patched version. All customers are strongly encouraged to ensure their websites have been updated to the latest version of Wordpress.
Our teams continue to work diligently to assess the impact of the recently disclosed WordPress Core vulnerabilities and verify that appropriate mitigation measures are in place. We remain actively engaged in our investigation and are monitoring the situation for any new developments.
We will continue to closely monitor the situation and take any additional steps necessary to maintain system security and stability. If you need assistance or have any concerns, please contact our Support team.
On July 17th Wordpress.org announced two critical remote code execution (RCE) vulnerabilities commonly known as WP2Shell. These vulnerabilities exist in Wordpress Core and allow an unauthenticated request to execute arbitrary code on the target website.
Customers running the Wordpress versions below are strongly advised to upgrade to latest version shown as soon as possible:
Wordpress 6.8.x; fixed in 6.8.6
WordPress 6.9.x; fixed in 6.9.5
WordPress 7.0.x; fixed in 7.0.2
WordPress 7.1 beta, fixed in 7.1 beta2
Source: https://wordpress.org/news/2026/07/wordpress-7-0-2-release/
With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.
Start free trialNo credit card required · Cancel anytime · 6320 services available
Integrations with