wp2shell Vulnerability Checker

Instantly check whether your WordPress site is running a version exposed to wp2shell - the critical, actively exploited pre-authentication RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137).

On July 17, 2026, WordPress patched wp2shell - a critical flaw that lets an anonymous attacker run code on a default WordPress site with no login, no plugins, and no user interaction. Public proof-of-concept exploits are already circulating and attacks are active in the wild. Digital Warfare checks the one thing that matters right now: whether your site's WordPress core version falls in the exposed range. Enter your URL and we read your public version information - the same data any visitor sees - then tell you in seconds whether you need to patch. No exploitation. No break-in. Just a clear answer and your next step.

Check My Site for wp2shell

No login required. Version check only. Results in seconds.

Run a free wp2shell check and know in seconds whether your WordPress site needs to be patched.

Check My Site for wp2shell

What the wp2shell Check Looks For

How It Works

Why wp2shell Is a "Patch Today" Emergency

wp2shell is a pre-authentication remote code execution chain in WordPress core. It combines a REST API batch-route confusion flaw (CVE-2026-63030) with a SQL injection in WP_Query (CVE-2026-60137) to let an unauthenticated attacker take over a default WordPress site. What makes it urgent:

  • It requires no account, no plugins, and no special configuration.
  • It affects WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1.
  • It was disclosed on July 17, 2026, and public proof-of-concept exploits appeared within hours.
  • Both CVEs were added to CISA's Known Exploited Vulnerabilities catalog on July 21, 2026, confirming active exploitation.
  • Because it lives in core - not a plugin - you can't deactivate your way out. You must update.

Your Result

We Test Version Numbers. We Never Exploit.

Digital Warfare's wp2shell check is strictly defensive. We determine your WordPress core version from information your site already makes public and compare it to the affected ranges - nothing more. We never send the wp2shell exploit, never attempt to run code, and never access anything a normal visitor couldn't see. Use it on sites you own or are authorized to test. It's a smoke detector, not a break-in.
Versions Affected

The full wp2shell remote code execution chain affects the following WordPress core versions:

  • WordPress versions below 6.9.0 — Not affected by the wp2shell RCE chain
  • WordPress 6.9.0 through 6.9.4 — Affected (fixed in 6.9.5)
  • WordPress 7.0.0 through 7.0.1 — Affected (fixed in 7.0.2)

Sites running any version outside the ranges above are not vulnerable to this specific RCE chain.

Note on the SQL injection component: One of the two flaws in the chain, CVE-2026-60137, is a SQL injection that independently affects WordPress 6.8.0 through 6.8.5 (fixed in 6.8.6). These versions are not exposed to the complete pre-authentication RCE, but should still be updated to close the underlying SQL injection.

Recommended Actions

The only reliable long-term protection is to update WordPress immediately.

  • Update to WordPress 6.9.5 or later if you are on the 6.9 branch.
  • Update to WordPress 7.0.2 or later if you are on the 7.0 branch.
  • Update to WordPress 6.8.6 or later if you are on the 6.8 branch, to close the related SQL injection (CVE-2026-60137).

WordPress enabled forced automatic updates for these releases. Because forced updates do not always complete — for example on sites with disabled auto-updates, file-permission issues, or custom configurations — confirm that your site is actually running a fixed version after updating.

Temporary mitigations (until the update is applied)

These reduce exposure but do not fix the underlying vulnerability. Apply the official update as soon as possible.

  1. Block the batch REST endpoint at your WAF or web server. Deny requests to the path /wp-json/batch/v1 and to the equivalent query-string form rest_route=/batch/v1 (used when pretty permalinks are disabled).
  2. Restrict unauthenticated access to the WordPress REST API. Prefer targeting the batch endpoint specifically — blanket-blocking the entire REST API can break the block editor, contact forms, and other legitimate features that rely on it.
  3. Require authentication for REST batch requests using a small custom (must-use) plugin that rejects unauthenticated calls to the batch route.

Each of these is a stopgap. Applying the official security update (6.9.5 / 7.0.2) remains the required solution.

Verify You're Protected

After updating or applying a mitigation, confirm it worked:

  • Check your version under Dashboard → Updates or in the admin footer, and confirm it is 6.9.5, 7.0.2, or later.
  • Re-run the wp2shell check to confirm your site reports a fixed version.
  • If you applied the WAF rule, confirm that requests to /wp-json/batch/v1 are blocked.
  • Retest on this page

Think You're Already Patched? Confirm It.

WordPress enabled forced automatic updates for the fixed releases - but forced updates don't always complete. Sites with disabled auto-updates, file-permission issues, or custom configurations can be left behind on a vulnerable version. A 30-second check confirms whether the patch actually landed on your site.

Built For

Why Digital Warfare

When a core WordPress vulnerability goes from disclosure to in-the-wild exploitation in a matter of hours, speed and clarity are everything. Digital Warfare tracks critical WordPress threats as they break and gives you a single, unambiguous answer: are you exposed, and what do you do next? No jargon, no fear-selling - just the fastest path from "not sure" to "secured."

Client Testimonials

  • "Since 2019, Digital Warfare has been our preferred vendor to conduct external Pen Testing on our SaaS Platforms. Saul and James are a pleasure to work with; their expertise in the cybersecurity space is impressive and their level of customer service and flexibility is unmatched among vendors. They are attentive, responsive, and thorough in everything they do!"

    - Nate Schlossberg, VP Engineering, Feedonomics / Big Commerce

  • "Digital Warfare has been a trusted partner in strengthening our cybersecurity posture through comprehensive and highly tailored penetration testing services. Their team goes beyond standard external testing by designing and executing advanced, scenario-based assessments, including targeted social engineering exercises, custom testing aligned to our internal application development, and validation of critical security controls across multiple layers of our environment ..."
    Read More

    - Arie Farhy, SVP, Chief Information Security Officer, Amerant Bank

  • S&T logo in dark blue on a white background
    "Digital Warfare is far more than a technical vendor - it is a true extension of our team at the bank. Our partnership has been both energizing and inspiring. Their team consistently challenges us to grow, helping us uncover opportunities for improvement while also celebrating our achievements and strengths. They bring thoughtful insight, trusted guidance, and a commitment to continuous refinement through retesting. Over the many years we’ve worked together, Digital Warfare has become an indispensable partner. Their expertise doesn’t just support our work - it elevates it. Quite simply, I can’t imagine navigating this industry without their collaboration and unwavering dedication."

    - Linda R. Foster Senior Vice President, Information Technology, S&T Bank

  • "I am so very appreciative of the work Digital Warfare did for us. I can’t say enough positive words about them."

    - Jared Waldrop, APRP, SVP | Operations Officer | ISO, Troy Bank & Trust

  • "We first used another company that had great marketing, sales people, and all the awards. They told us we were fine and found nothing, which seemed suspicious but sounded that maybe we did well. Then someone who called themselves a "security researcher" reached out and showed us that we had a ton of holes in our web application and other areas. After wasting a ton of money on the first pen testing company (who would not refund our money), we asked around and the name Digital Warfare kept coming up as highly recommended. They found things that made us squirm but we are glad they found them before a bad guy did. We highly recommend this firm to anyone looking for the real deal."

    - David Price, Delphinus Capital

  • "After reviewing different providers, we chosen Digital Warfare to perform penetration tests and Microsoft 365 security analysis. We couldn’t be happier with that decision! The job has been done in time and manner, including several calls to review results, re-tests, and monthly vulnerability checks. We have established a relationship where we have Digital Warfare as a key partner and our main security advisor. We plan to do more projects together."

    - Juan Rosli, Director of Technology, Accial Capital

  • "Digital Warfare has been an essential partner in our security endeavors for the past 3 years. They are professional, knowledgeable, and above-all, excellent at what they do!"

    - Thomas L Stanley, Principal Site Reliability Engineer, Technical Lead, Schedulicity.com

×

Digital Warfare has been a trusted partner in strengthening our cybersecurity posture through comprehensive and highly tailored penetration testing services. Their team goes beyond standard external testing by designing and executing advanced, scenario-based assessments, including targeted social engineering exercises, custom testing aligned to our internal application development, and validation of critical security controls across multiple layers of our environment.

What differentiates Digital Warfare is their ability to translate complex technical findings into actionable risk insights. Their assessments provide clear, evidence-based results that allow us to confidently prioritize remediation efforts and align them with our broader security strategy and risk appetite. The depth and quality of their testing have not only identified vulnerabilities but also validated the effectiveness of our controls in real-world attack scenarios.

Additionally, their collaborative approach and strong technical expertise have significantly contributed to the ongoing maturation of our cybersecurity program. Their work has helped us strengthen our defensive capabilities, enhance our detection and response readiness, and improve overall resilience against evolving threats.

We value Digital Warfare as a strategic partner that consistently delivers high-quality, risk-focused outcomes and helps elevate our cybersecurity posture in a measurable and meaningful way.

- Arie Farhy, SVP, Chief Information Security Officer, Amerant Bank

Don't Wait for the Attack. Check Now.

Run a free wp2shell check and know in seconds whether your
WordPress site needs to be patched.

Check My Site for wp2shell

wp2shell FAQ

Frequently Asked Questions

1What is wp2shell?
wp2shell is a critical pre-authentication remote code execution (RCE) vulnerability in WordPress core, disclosed on July 17, 2026. It lets an anonymous attacker run code on a default WordPress site with no login, no plugins, and no user interaction. Technically it's a chain of two flaws: CVE-2026-63030 and CVE-2026-60137.
2What are CVE-2026-63030 and CVE-2026-60137?
CVE-2026-63030 is a REST API batch-route confusion flaw in WordPress core. CVE-2026-60137 is a SQL injection flaw in the author__not_in parameter of WP_Query. Chained together, they allow unauthenticated remote code execution against affected WordPress installations.
3Which WordPress versions are affected by wp2shell?
The full wp2shell RCE chain affects WordPress 6.9.0 through 6.9.4 and 7.0.0 through 7.0.1. The SQL-injection component (CVE-2026-60137) also affects 6.8.0 through 6.8.5. The fixed versions are 6.9.5, 7.0.2, and 6.8.6, all released July 17, 2026.
4How do I know if my WordPress site is vulnerable to wp2shell?
Check your WordPress core version. If it's in an affected range and hasn't been updated to a fixed release, it's exposed. Digital Warfare's checker reads your site's public version and gives you the answer in seconds.
5How do I fix / patch wp2shell?
Update WordPress core to 6.9.5, 7.0.2, or later (or 6.8.6 on the 6.8 branch). WordPress enabled forced automatic updates for these releases, but you should confirm the update actually completed on your site.
6Is wp2shell being actively exploited?
Yes. Multiple security firms confirmed in-the-wild exploitation within days of disclosure, public proof-of-concept exploits are circulating, and both CVEs were added to CISA's Known Exploited Vulnerabilities catalog on July 21, 2026.
7Does this checker exploit my site?
No. It only reads your site's public WordPress version and compares it to the affected ranges. It never sends the exploit, runs code, or accesses anything a normal visitor couldn't already see.
8I have automatic updates turned on - am I safe?
Probably, but confirm it. Forced auto-updates can fail to complete on sites with disabled updates, permission issues, or custom configurations. A quick version check verifies the patch actually landed.
9My site was running a vulnerable version - what should I do now?
Patch immediately, then review your site for signs of compromise: unexpected administrator accounts, unfamiliar plugins or files, and unusual REST API activity on the /wp-json/batch/v1 endpoint. If you find anything suspicious or aren't sure, engage an incident-response professional.
10Does the check work on any WordPress site?
It's intended for sites you own or are authorized to test. It's a defensive tool for confirming your own exposure - not for scanning sites you don't control.

wp2shell - Key Facts

  • wp2shell is a critical pre-authentication RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137).
  • It affects WordPress 6.9.0–6.9.4 and 7.0.0–7.0.1; the SQL-injection component also affects 6.8.0–6.8.5.
  • It is fixed in WordPress 6.9.5, 7.0.2, and 6.8.6 (released July 17, 2026).
  • It requires no login, no plugins, and no user interaction.
  • It is being actively exploited; both CVEs are in CISA's KEV catalog as of July 21, 2026.
  • Digital Warfare's checker tests your WordPress core version only - no exploitation.

 

Contact Us Now to Prepare
for Digital Warfare