28/07/2026
It's certainly been one of those weeks! 😵💫😫
If you own a WordPress website, it's worth making yourself aware of the recent critical security vulnerability affecting WordPress, tracked as CVE-2026-63030 (also known as "wp2shell").
This vulnerability affected out of date versions of WordPress worldwide and highlighted just how important it is to keep WordPress core, plugins and themes regularly updated. It's no different to keeping your mobile phone or computer up to date with the latest security updates.
Over the past five days, I've been working through all of my clients' websites - restoring sites where necessary, updating WordPress core and plugins, taking fresh backups and carrying out thorough security checks to ensure they're fully protected. It's certainly been a busy few days, but the peace of mind knowing they're secure again has made it worthwhile.
This incident has reinforced why website maintenance is no longer something that can be overlooked. A website isn't something you can simply build and leave for years without ongoing care.
If you'd like to read more about the wp2shell vulnerability, here's a good explanation...
⚠ Stay vigilant, everyone! ⚠
wp2shell is a pre-auth RCE in WordPress Core (CVE-2026-63030 + CVE-2026-60137). How it works, affected versions, PoC, detection and remediation.