19 July 2026
1. What is being reported?
Security researchers have discovered vulnerabilities in the core WordPress software that let attackers execute commands on your website without permission. These are known as remote code execution (RCE) flaws. Public details and exploit tools are now available, making it easier for attackers to target unpatched sites.
2. What this means in plain English
If your website runs on WordPress and is not updated, attackers could take control of it, steal information, or use it to attack others. This can lead to loss of customer trust, website downtime, and potential legal issues if data is compromised.
3. Could this affect a small business?
Any small business, charity, or club using WordPress for their website could be affected if they have not applied the latest updates. Organisations not using WordPress or those whose websites are managed by professional providers who keep software updated are less likely to be at risk.
4. What to do now
- Check if your website uses WordPress and identify its current version.
- Apply the latest WordPress updates and security patches immediately.
- If you use a web hosting or IT provider, ask them to confirm your site is updated.
- Regularly back up your website and monitor for unusual activity.
5. Ask your IT provider
Has our WordPress website been updated to fix the 'wp2shell' remote code execution vulnerability?
6. Bottom line
Keep your WordPress site updated now to protect your organisation from serious security risks.
Information based on reputable security reporting and CISA Known Exploited Vulnerabilities list.