Use cases
Software Products E-commerce MSPs Schools Development & Marketing DevOps Agencies Help Desk
Company
Internet Status Blog Pricing Log in Get started free

Outage in Nexcess

Security Advisory: Critical WordPress Vulnerability - "Click2Shell"

Resolved Minor
September 22, 2026 - Started 9 days ago - Lasted 3 days
Official incident page

Incident Report

Summary AI Generated

WordPress disclosed a critical Remote Code Execution vulnerability ("Click2Shell") affecting all versions prior to 7.1.1, later compounded by a second critical vulnerability (CVE-2026-87902) requiring an additional update to version 7.1.2. All WordPress installations hosted on Nexcess were at risk across the entire hosting fleet. Nexcess engineers automatically upgraded affected sites where possible, with tickets issued to customers whose sites could not be automatically updated, and all customers were advised to manually verify their WordPress versions were updated to 7.1.2.

WordPress has identified a critical security vulnerability designated as "Click2Shell" affecting all WordPress versions prior to 7.1.1. This vulnerability can enable unauthenticated Remote Code Execution (RCE) when a logged-in administrator visits a specially crafted link. Current Status & Hosting Actions Our engineering team is currently assessing our entire hosting fleet and determining next steps. There are currently no known workarounds for this vulnerability other than upgrading to the latest version of WordPress. Recommended Action for Customers We strongly advise all customers managing WordPress installations to review their environments immediately and update to WordPress version 7.1.1. We will continue to monitor the situation closely and provide further updates as new information becomes available.

Trusted by 1,000+ teams

The Status Page Aggregator with Early Outage Detection

Stop finding out about outages from your users. Monitor 6,320+ cloud services and get alerted the second something breaks.

IsDown status aggregator dashboard
Latest Updates ( sorted recent to last )
RESOLVED 6 days ago - at 09/25/2026 07:19PM

As part of our proactive security efforts, Nexcess System Engineers scanned our fleet and automatically upgraded WordPress installations where possible to the appropriate patched versions. Automated update attempts were unsuccessful for some websites due to site-specific errors. Customers with websites that were unable to be upgraded should receive a ticket identifying the server and path to the website.

All customers are strongly encouraged to confirm the Wordpress version for all of the websites, including those in staging or development, have been updated to the latest minor version of Wordpress released on September 22nd in order to protect the website from this exploit.

For additional information, please refer to the official WordPress security announcements:
https://wordpress.org/news/2026/09/wordpress-7-1-2-release/
https://wordpress.org/documentation/wordpress-version/version-7-1-2/

If you have any questions or need assistance with the update process, please contact our Support team. You can reach us through the following channels:

Live Chat via the Customer Portal: https://my.nexcess.net/
Email: support@nexcess.net

We appreciate your patience and understanding as we work to secure your services.

IDENTIFIED 8 days ago - at 09/23/2026 06:35AM

Our Engineering team continues to assess and work on the WordPress security vulnerabilities across our hosting fleet.

A new critical vulnerability, CVE-2026-87902, has been disclosed. WordPress 7.1.2 includes the security fix for this vulnerability.

Recommended Action for Customers

We strongly advise all customers managing WordPress installations to update to WordPress version 7.1.2 immediately.

We will continue to monitor the situation closely and provide further updates as new information becomes available.

INVESTIGATING 9 days ago - at 09/22/2026 08:13PM

WordPress has identified a critical security vulnerability designated as "Click2Shell" affecting all WordPress versions prior to 7.1.1. This vulnerability can enable unauthenticated Remote Code Execution (RCE) when a logged-in administrator visits a specially crafted link.
Current Status & Hosting Actions

Our engineering team is currently assessing our entire hosting fleet and determining next steps.

There are currently no known workarounds for this vulnerability other than upgrading to the latest version of WordPress.

Recommended Action for Customers

We strongly advise all customers managing WordPress installations to review their environments immediately and update to WordPress version 7.1.1.

We will continue to monitor the situation closely and provide further updates as new information becomes available.

The Status Page Aggregator with Early Outage Detection

With IsDown, you can monitor all your critical services' official status pages from one centralized dashboard and receive instant alerts the moment an outage is detected. Say goodbye to constantly checking multiple sites for updates and stay ahead of outages with IsDown.

Start free trial

No credit card required · Cancel anytime · 6320 services available

Integrations with Slack Microsoft Teams Google Chat Datadog PagerDuty Zapier Discord Webhook