WordPress had a vulnerability called wp2shell. Static sites were never in scope.
In July 2026, a bug in WordPress core let an anonymous attacker run code on almost any unpatched site, no plugins, no login, no warning. It's already being exploited. A Keep site was never exposed, not because of faster patching, but because there was nothing for this vulnerability to attack.
01 - What Happened
A core WordPress bug, not a plugin problem.
On 17 July 2026, security researchers disclosed a vulnerability in WordPress core, publicly named wp2shell. It chains two separate flaws, tracked as CVE-2026-60137 and CVE-2026-63030, in a way that lets an anonymous, unauthenticated attacker run code directly on the server.
WordPress shipped emergency fixes in versions 6.9.5 and 7.0.2, and enabled forced automatic updates given the severity. Multiple security research teams confirmed active exploitation in the wild, some of it before a public proof-of-concept even existed.
WordPress runs a substantial share of the entire web. This bug affected all of it, regardless of which plugins were or weren't installed.
02 - The Uncomfortable Part
"We don't use many plugins" was not a defence.
Most WordPress security advice focuses on plugins, keep them updated, remove ones you don't need, avoid untrusted ones. That advice is generally sound, and it would not have helped here.
wp2shell lives in WordPress core itself. A stock installation, freshly set up, with zero plugins added, was exploitable. The usual reasoning, "we keep things minimal, so we're lower risk," did not apply to this bug at all.
That's the part worth sitting with. The attack surface wasn't a choice anyone made. It was built into the platform everyone was standing on.
03 - Why Keep Sites Were Unaffected
Not faster patching. Nothing to patch.
Every Keep site is hand-coded and served as static files. That single decision removes the entire mechanism wp2shell depends on.
No PHP Interpreter
wp2shell achieves code execution through server-side PHP. A static site has no PHP running on the server at all, nothing to execute.
No WordPress Core
The vulnerability lives in WordPress's own codebase. A site that was never built on WordPress cannot inherit a bug from it.
No Database To Inject
Part of the chain relies on a SQL injection. Static sites have no database sitting behind the page, so there is nothing to inject into.
No Plugin Directory
Attackers used this class of bug to drop malicious files into a plugins folder. Static sites have no plugin ecosystem for anything to be dropped into.
04 - Common Questions
wp2shell, plainly answered.
What is wp2shell?
wp2shell is a critical vulnerability disclosed in July 2026 affecting WordPress core itself, not a plugin. It chains two flaws, tracked as CVE-2026-60137 and CVE-2026-63030, allowing an anonymous attacker to run code on a stock WordPress installation with no plugins and no special configuration.
Do I need plugins installed to be affected by wp2shell?
No. wp2shell affects WordPress core. A bare install with zero plugins was exploitable. This is different from most WordPress security incidents, which usually involve a vulnerable third-party plugin.
How do I know if my WordPress site is affected?
Affected versions are 6.9.0 to 6.9.4 and 7.0.0 to 7.0.1. WordPress released fixes in 6.9.5 and 7.0.2. Check your installed version and confirm it has actually updated, do not assume an automatic update has completed.
Why weren't static websites affected by wp2shell?
wp2shell exploits WordPress's PHP codebase and database layer. A static website has no PHP interpreter running server-side and no database to query, so the mechanism the vulnerability relies on does not exist on that kind of site. This is not a matter of faster patching, there was never a matching attack surface.
Still running WordPress?
If your site's version hasn't been confirmed patched, that's worth checking today, not this weekend. And if you'd rather stop having this conversation every time WordPress core has a bad week, a static rebuild removes the question entirely.
Get a Website Check →