
In July 2026, security researchers raised the alarm about a WordPress attack nicknamed "wp2shell." Within days, automated bots were scanning the internet and hitting tens of thousands of websites. If you run a WordPress site and you have seen the name pop up, here is what it actually means, in plain English, and whether you need to do anything about it.
wp2shell is a way for attackers to take over a WordPress website without needing a username or password. It chains together two flaws in unpatched versions of WordPress (tracked as CVE-2026-63030 and CVE-2026-60137) to slip a hidden file onto the site. That file is called a "web shell," and it quietly hands the attacker the keys to the whole website.
Think of a web shell as a secret back door. Once it is installed, an attacker can come and go whenever they like, without ever touching your login page. From there they can read your data, create fake admin accounts, send spam, inject scam links, redirect your visitors to dodgy sites, or quietly use your server to attack others. To make things trickier, some versions of the wp2shell back door disguise themselves as a legitimate "security" plugin, so a quick glance at the dashboard looks perfectly normal.
For most people the honest answer is: only if your site is not kept up to date. The flaw lives in specific WordPress versions, and WordPress released a fix quickly. Updating to 6.9.5, 7.0.2 or later closes the hole completely. The sites getting hit are the ones running old, unpatched software. Outdated, unmaintained, and "set and forget" WordPress sites are the easy targets. If your site is patched and actively maintained, you are protected.
Every Bang Media client is on the latest, patched version of WordPress, so their sites are not exposed to wp2shell.
None of these on their own prove an infection, but if you notice a few together, it is worth looking closer.
Keeping a WordPress site secure is not a one-off job, it is ongoing maintenance. We keep our clients' sites on the latest versions, watch for problems, and step in quickly when something looks off.
If you are concerned your site might be infected with wp2shell, or anything else, reach out and we can investigate for you. We will check the site over, tell you plainly where you stand, and clean it up if needed.
Get in touch and we'll take a look.
