WordPress wp2shell: SMB Website Patch Verification

Verify WordPress 7.0.2, 6.9.5, or 6.8.6 after exploitation of CVE-2026-63030 and CVE-2026-60137, then investigate for persistence when exposure is plausible.

Back to Blog
(Updated )
2 min read
Conceptual illustration of a single web request slipping past a WordPress site's defenses to plant a shell

WordPress released security updates on July 17, 2026 for CVE-2026-63030 and CVE-2026-60137. CISA added both vulnerabilities to the Known Exploited Vulnerabilities catalog on July 21. Updating WordPress closes the known flaws; it does not remove a shell or account created before the update.

Current as of 2026-08-15

WordPress 7.0.2 release guidance identifies fixed releases 7.0.2, 6.9.5, and 6.8.6 and says versions before 6.8 are unaffected. WordPress initiated forced background updates for affected branches.

Decision summary

  • Verify the installed WordPress core version rather than trusting an update notification.
  • Confirm every production, staging, development, and abandoned instance.
  • Investigate for persistence when an affected site was exposed before patching.
  • Update plugins, themes, PHP, and hosting controls separately; the core update does not remediate unrelated risk.

Resolve the exact core version

Record the WordPress version from the running site and deployment artifact. Supported fixed branches are 7.0.2, 6.9.5, and 6.8.6. Versions before 6.8 are not affected by these two CVEs, but they may be unsupported or exposed to other vulnerabilities.

Verify every copy

  • Public production sites.
  • Staging and development hosts.
  • Old domains and subdomains.
  • Temporary migration copies.
  • Backup restorations and golden images.
  • Sites operated by a marketing or hosting vendor.

Patch safely

  1. Create a current backup and verify restore access.
  2. Apply the supported WordPress core update.
  3. Confirm the running version and filesystem state.
  4. Test login, forms, ecommerce, integrations, and scheduled jobs.
  5. Keep rollback evidence while checking for compromise.

Look for persistence

Review administrator accounts, recently modified PHP files, uploads containing executable content, plugins, themes, scheduled tasks, web-server configuration, access logs, outbound traffic, and hosting control-panel activity. Compare core files with trusted packages. Preserve evidence before deleting suspicious artifacts.

Escalate when evidence appears

A web shell or unauthorized administrator is an incident, not a cleanup ticket. Isolate the site where safe, preserve logs and files, rotate exposed credentials and secrets, assess connected databases and services, and rebuild from a trusted source when integrity cannot be established.

For related guidance from ITECS, see ITECS cybersecurity services.

Sources and update trigger

Review trigger: Recheck the WordPress release post and CISA KEV entry when new fixed releases, exploitation details, or indicators appear.

continue reading

More ITECS blog articles

Browse all articles

About ITECS Team

The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.

View full profile and articles

Share This Article

Continue Reading

Explore more insights and technology trends from ITECS

View All Articles